7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43722
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_status_groups_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-3229
fossbilling/fossbilling General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.

CVE-2023-26688
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.

CVE-2023-0150
Cloak Front End Email Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-49976
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket.

CVE-2023-4646
Simple Posts Ticker Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43725
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_name_long[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0438
modoboa/modoboa Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-0542
Custom Post Type List Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0230
VK All in One Expansion Unit Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43874
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.

CVE-2023-0072
WC Vendors Marketplace Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-26843
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
12.4%
2023 1 PoC

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.

CVE-2023-0033
PDF Viewer Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2023-51157
Software Genérico General
5.4
MEDIUM
EPSS
0.8%
2023 1 PoC

Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.

CVE-2023-0891
StagTools Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0095
Page View Count Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-30057
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-3521
fossbilling/fossbilling Web ⚡ nuclei
5.4
MEDIUM
EPSS
19.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.

CVE-2023-26131
github.com/xyproto/algernon/engine Web
5.4
MEDIUM
EPSS
0.3%
2023 CWE-79 2 PoCs

All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. Exploiting this vulnerability is possible when a file/resource is not found.