7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6094
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9881
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13128
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10475
Responsive Contact Form Builder & Lead Generation Plugin Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3918
Pet Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks.

CVE-2024-5968
Photo Gallery by 10Web Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5561
Popup Maker Web Windows
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6693
wccp-pro Web Windows
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2869
Easy Property Listings Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-23818
geoserver Web
4.8
MEDIUM
EPSS
0.5%
2024 CWE-79 1 PoC

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.3 and 2.24.1 that enables an authenticated administrator with workspace-level privileges to store a JavaScript payload in the GeoServer catalog that will execute in the context of another user's browser when viewed in the WMS GetMap OpenLayers Output Format. Access to the WMS OpenLayers Format is available to all users by default although data and service security may limit users' ability to trigger

CVE-2024-7133
Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme Web Windows
4.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputting them back in the page, which could allow users with a high role to perform Stored Cross-Site Scripting attacks.

CVE-2024-0951
Advanced Social Feeds Widget & Shortcode Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6498
Chatbot for WordPress by Collect.chat ⚡️ Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-5029
CM Table Of Contents Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-7084
Ajax Search Lite Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.

CVE-2024-3582
UnGallery Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-4621
ARForms - Premium WordPress Form Builder Plugin Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3634
month name translation benaceur Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-42901
Software Genérico General
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.

CVE-2024-13383
HD Quiz Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).