7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22116
directus Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in a victim’s browser when they open the image URL.

CVE-2022-4649
WP Extended Search Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-35134
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.

CVE-2022-4787
Themify Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4781
Accordion Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-44948
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.7%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".

CVE-2022-3984
Flowplayer Video Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-43097
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages.

CVE-2022-4491
WP-Table Reloaded Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.

CVE-2022-43169
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
7.3%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Group".

CVE-2022-3002
yetiforcecompany/yetiforcecrm Web
5.4
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE-2022-40348
Software Genérico Web
5.4
MEDIUM
EPSS
0.7%
2022 1 PoC

Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code.

CVE-2022-22117
directus Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.

CVE-2022-35500
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.

CVE-2022-23065
vendure Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.

CVE-2022-44950
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2022-22402
Aspera Faspex Web
5.4
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 222571.

CVE-2022-4760
OneClick Chat to Order Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4655
Welcart e-Commerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.

CVE-2022-4626
PPWP Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.