7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-26521
Software Genérico Web
4.8
MEDIUM
EPSS
1.9%
2024 1 PoC

HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component.

CVE-2024-2872
socialdriver-framework Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-7052
Forminator Forms Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12874
Top Comments Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12872
Zalomení Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3921
Gianism Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-50857
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.

CVE-2024-2444
Inline Related Posts Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-5026
CM Tooltip Glossary Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-7878
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7758
Stylish Price List Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12716
Simple Basic Contact Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12808
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10517
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Web Windows
4.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6927
Viral Signup Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6158
Category Posts Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12743
MailPoet Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8052
Review Ratings Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-9390
RegistrationMagic Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6061
GPAC General
4.8
MEDIUM
EPSS
0.0%
2024 CWE-835 1 PoC

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is 20c0f29139a82779b86453ce7f68d0681ec7624c. It is recommended to apply a patch to fix this issue. The identifier VDB-268789 was assigned to this vulnerability.