5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-0627
WordPress Tag, Category, and Taxonomy Manager Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-1203
Slider, Gallery, and Carousel by MetaSlider Web Windows
3.5
LOW
EPSS
0.0%
2025 1 PoC

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-49810
Mattermost General
3.5
LOW
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts

CVE-2025-9543
FlexTable Web Windows
3.5
LOW
EPSS
0.0%
2025 1 PoC

The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-30345
OpenSlides General
3.5
LOW
EPSS
0.2%
2025 CWE-116 1 PoC

An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most cases, HTML entities are encoded properly, but not when deleting chats or deleting messages in these chats. This potentially allows attackers to interfere with the layout of the rendered website, but it is unlikely that victims would click on deleted chats or deleted messages.

CVE-2025-1623
GDPR Cookie Compliance Web Windows
3.5
LOW
EPSS
0.1%
2025 1 PoC

The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-1622
GDPR Cookie Compliance Web Windows
3.5
LOW
EPSS
0.1%
2025 1 PoC

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-3502
WP Maps Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-1524
Ultimate Dashboard Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-30259
WhatsApp cloud service Cloud
3.5
LOW
EPSS
0.1%
2025 1 PoC

The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL.

CVE-2025-8282
SureForms Web Windows
3.5
LOW
EPSS
0.0%
2025 1 PoC

The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the page, which could allow admin and above users to perform Cross-Site Scripting attacks.

CVE-2025-3513
SureForms Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-0717
Social Slider Feed General
3.5
LOW
EPSS
0.1%
2025 1 PoC

To exploit the vulnerability, it is necessary:

CVE-2025-62780
changedetection.io Web ⚡ nuclei
3.5
LOW
EPSS
0.1%
2025 CWE-79 0 PoCs

changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in changedetection.io Watch update API in versions prior to 0.50.34 due to insufficient security checks. Two scenarios are possible. In the first, an attacker can insert a new watch with an arbitrary URL which really points to a web page. Once the HTML content is retrieved, the attacker updates the URL with a JavaScript payload. In the second, an attacker substitutes the URL in an existing watch with a new URL that is in reality a JavaScript payload. When the user clicks on *Previe

CVE-2025-3514
SureForms Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-0692
Simple Video Management System Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-58084
Mattermost General
3.5
LOW
EPSS
0.1%
2025 CWE-1287 1 PoC

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.

CVE-2025-66823
Software Genérico General
3.5
LOW
EPSS
0.1%
2025 1 PoC

An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).

CVE-2025-3504
WP Maps Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-1062
Slider, Gallery, and Carousel by MetaSlider Web Windows
3.5
LOW
EPSS
0.1%
2025 1 PoC

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).