7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0892
BizLibrary Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-24231
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Categories Name parameter.

CVE-2023-0157
All-In-One Security (AIOS) Web Windows
4.8
MEDIUM
EPSS
25.1%
2023 2 PoCs

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this page.

CVE-2023-1323
Easy Forms for Mailchimp Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5943
Wp-Adv-Quiz Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2023-2995
Leyka Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2684
File Renaming on Upload Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0420
Custom Post Type and Taxonomy GUI Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF

CVE-2023-2113
Autoptimize Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup.

CVE-2023-3245
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0756
GitLab DevOps
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVE-2023-0894
Pickup | Delivery | Dine-in date time Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4060
WP Adminify Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Adminify WordPress plugin before 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1120
Simple Giveaways Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1525
Site Reviews Web Windows
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-1090
SMTP Mailing Queue Web Windows
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4253
AI ChatBot Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2954
liangliangyy/djangoblog Web
4.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.

CVE-2023-5529
Advanced Page Visit Counter Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4298
123.chat Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The 123.chat WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)