7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5229
E2Pdf Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2023-1319
osticket/osticket Web
4.8
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-5842
dolibarr/dolibarr Web
4.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.

CVE-2023-53880
Lucee Web
4.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through administrative interface parameters. Attackers can craft specific payloads targeting admin pages like server.cfm and web.cfm to execute arbitrary JavaScript in victim's browser sessions.

CVE-2023-0422
Article Directory Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before displaying it in the administration panel, which may enable administrators to conduct Stored XSS attacks in multisite contexts.

CVE-2023-0756
GitLab DevOps
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVE-2023-3647
IURNY by INDIGITALL Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5137
Simply Excerpts Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

CVE-2023-6046
EventON Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.

CVE-2023-24230
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the component /formwork/panel/dashboard of Formwork v1.12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page title parameter.

CVE-2023-6005
EventON Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5243
Login Screen Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-0949
modoboa/modoboa Web
4.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.5.

CVE-2023-6163
WP Crowdfunding Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-24231
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Categories Name parameter.

CVE-2023-0892
BizLibrary Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0157
All-In-One Security (AIOS) Web Windows
4.8
MEDIUM
EPSS
25.1%
2023 2 PoCs

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this page.

CVE-2023-1323
Easy Forms for Mailchimp Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5943
Wp-Adv-Quiz Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2023-2995
Leyka Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)