7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-38687
svelecte Web
5.4
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML with no escaping. This allows the injection of arbitrary HTML into the Svelecte dropdown. This can be exploited to execute arbitrary JavaScript whenever a Svelecte dropdown is opened. Item names given to Svelecte appear to be directly rendered as HTML by the default item renderer. This means that any HTML tags in the name are rendered as HTML elements not as text. Note that the custom item renderer shown in https://mskocik.github.io/svelecte/#item-rendering is also vulnerable to

CVE-2023-6503
WP Plugin Lister Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-25448
Archivist – Custom Archive Templates Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.

CVE-2023-52059
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field.

CVE-2023-43713
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.

CVE-2023-0367
Pricing Tables For WPBakery Page Builder (formerly Visual Composer) Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-25440
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.

CVE-2023-0144
Event Manager and Tickets Selling Plugin for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0097
Post Grid, Post Carousel, & List Category Posts Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0604
WP Food Manager Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Food Manager WordPress plugin before 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-43716
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MAX_DISPLAY_NEW_PRODUCTS_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-43729
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "xsell_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-4757
Staff / Employee Business Directory for Active Directory Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

CVE-2023-30094
Software Genérico Web
5.4
MEDIUM
EPSS
0.8%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the settings module.

CVE-2023-45828
RumbleTalk Live Group Chat General
5.4
MEDIUM
EPSS
4.7%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in RumbleTalk RumbleTalk Live Group Chat rumbletalk-chat-a-chat-with-themes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through <= 6.2.5.

CVE-2023-46615
KD Coming Soon General
5.4
MEDIUM
EPSS
5.6%
2023 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

CVE-2023-43458
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the room, name, and description parameters in the manage_room function.

CVE-2023-30097
Software Genérico Web
5.4
MEDIUM
EPSS
0.8%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field.

CVE-2023-0059
Youzify Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1875
thorsten/phpmyfaq Web
5.4
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.