7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-9663
CYAN Backup Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-37395
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.

CVE-2024-8854
Polls CP Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

CVE-2024-0881
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
13.1%
2024 1 PoC

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

CVE-2024-34899
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).

CVE-2024-4372
Carousel Slider Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-6134
wp-cart-for-digital-products Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-39248
Software Genérico Web
5.4
MEDIUM
EPSS
1.5%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field at /admin.php.

CVE-2024-30989
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter.

CVE-2024-8239
Starbox Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.

CVE-2024-25974
OpenOlat LMS Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-20 2 PoCs

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can be uploaded. After a successful upload the file can be shared with groups of users (including admins) who can be attacked with the JavaScript payload.

CVE-2024-46081
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.

CVE-2024-33210
Software Genérico Web
5.4
MEDIUM
EPSS
2.9%
2024 1 PoC

A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.

CVE-2024-42918
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.

CVE-2024-4094
Simple Share Buttons Adder Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-48392
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 2 PoCs

OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.

CVE-2024-53364
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.

CVE-2024-25973
OpenOlat LMS Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-20 2 PoCs

The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a name that contains an XSS payload. Furthermore, attackers with the permissions to create or rename a catalog (sub-category) can enter unfiltered input in the name field. In addition, attackers who are allowed to create curriculums can also enter unfiltered input in the name field. This allows an attacker to execute stored JavaScript code with the permissions of the victim in the context of the user's browser.

CVE-2024-29386
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.

CVE-2024-3752
Crelly Slider Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)