7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-7918
Pocket Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5799
CM Pop-Up Banners for WordPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.

CVE-2024-8187
Smart Post Show Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9227
PowerPress Podcasting plugin by Blubrry Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2024-3986
SportsPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The SportsPress WordPress plugin before 2.7.22 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13486
Icegram Engage Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-45960
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.

CVE-2024-13605
Form Maker by 10Web Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3822
Base64 Encoder/Decoder Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-6724
Generate Images Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-11605
wp-publications Web Windows
4.8
MEDIUM
EPSS
2.0%
2024 1 PoC

The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11266
Geocache Stat Bar Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13127
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12567
Email Subscribers by Icegram Express Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11261
Student Record Management System General
4.8
MEDIUM
EPSS
0.1%
2024 CWE-119 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Student Record Management System 1.0. Affected is an unknown function of the file StudentRecordManagementSystem.cpp of the component Number of Students Menu. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVE-2024-21500
github.com/greenpau/caddy-security General
4.8
MEDIUM
EPSS
0.0%
2024 CWE-307 1 PoC

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism by automating the application’s full multistep 2FA process.

CVE-2024-5658
CraftCMS Plugin - Two-Factor Authentication Web
4.8
MEDIUM
EPSS
0.2%
2024 CWE-303 1 PoC

The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.

CVE-2024-6094
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6783
vue Web
4.8
MEDIUM
EPSS
0.3%
2024 CWE-79 2 PoCs

A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code.

CVE-2024-10107
Giveaways and Contests by RafflePress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).