7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43715
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-5323
dolibarr/dolibarr Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.

CVE-2023-43343
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Files - Description parameter in the Pages Menu component.

CVE-2023-1146
flatpressblog/flatpress Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-0434
pyload/pyload General
5.4
MEDIUM
EPSS
0.5%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40.

CVE-2023-0081
MonsterInsights Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0078
Resume Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users

CVE-2023-6379
Open CMS Web ⚡ nuclei
5.4
MEDIUM
EPSS
18.6%
2023 CWE-79 0 PoCs

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.

CVE-2023-0168
Olevmedia Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2105
alextselegidis/easyappointments General
5.4
MEDIUM
EPSS
0.8%
2023 CWE-384 1 PoC

Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

CVE-2023-43735
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "formats_titles[7]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0270
YaMaps for WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1383
Fire TV Stick 3rd gen Windows
5.4
MEDIUM
EPSS
0.4%
2023 CWE-841 1 PoC

An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

CVE-2023-0176
Giveaways and Contests by RafflePress Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-21921
Health Sciences InForm Web Database
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data. CVSS

CVE-2023-4821
Drag and Drop Multiple File Upload for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

CVE-2023-25440
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.

CVE-2023-0559
GS Portfolio for Envato Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-33408
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Minical 1.0.0 is vulnerable to Cross Site Scripting (XSS). The vulnerability exists due to insufficient input validation in the application's user input handling in the security_helper.php file.

CVE-2023-33764
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component #/de/casting/show/detail/<ID>.