7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0066
Companion Sitemap Generator Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-29506
xwiki-platform General ⚡ nuclei
5.4
MEDIUM
EPSS
11.5%
2023 CWE-79 1 PoC

XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

CVE-2023-0368
Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-50072
Software Genérico Web
5.4
MEDIUM
EPSS
3.7%
2023 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.

CVE-2023-32751
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
1.0%
2023 2 PoCs

Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaScript [1]. The secrets used to sign these URLs are hardcoded and exposed through the JavaScript files of the web application. Therefore, it is possible to generate valid signatures for arbitrary download URLs. By uploading an HTML file and modifying the download URL to serve the file inline instead of as an attachment, any included JavaScript code is executed when the URL is opened in a browser, leading to a cross-site scripting vulnerabi

CVE-2023-0362
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-23635
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2023 1 PoC

In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.

CVE-2023-6571
kubeflow/kubeflow Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow

CVE-2023-22050
JD Edwards EnterpriseOne Orchestrator Web Database
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.7.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Orchestrator accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Orchestrator access

CVE-2023-1019
Help Desk WP Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.

CVE-2023-29918
Software Genérico General
5.4
MEDIUM
EPSS
5.9%
2023 1 PoC

RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.

CVE-2023-49977
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.

CVE-2023-3982
omeka/omeka-s Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2.

CVE-2023-0379
Spotlight Social Feeds [Block, Shortcode, and Widget] Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0372
EmbedStories Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-49987
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.

CVE-2023-31434
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 2 PoCs

The parameters nutzer_titel, nutzer_vn, and nutzer_nn in the user profile, and langID and ONLINEID in direct links, in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 do not validate input, which allows authenticated attackers to inject HTML Code and XSS payloads in multiple locations.

CVE-2023-0366
Loan Comparison Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-24769
Software Genérico Web
5.4
MEDIUM
EPSS
0.8%
2023 2 PoCs

Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.

CVE-2023-23851
Business Planning and Consolidation General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-434 1 PoC

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.