2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1905MEDIUM5.4The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page short...
CVE-2023-1806MEDIUM6.1The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outp...
CVE-2023-1660MEDIUM6.1The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing...
CVE-2023-1651MEDIUM5.4The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to upda...
CVE-2023-1650CRITICAL9.8The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauth...
CVE-2023-1649MEDIUM4.8The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow hi...
CVE-2023-1408HIGH7.2The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in...
CVE-2023-1347HIGH7.2The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which coul...
CVE-2023-1011MEDIUM6.1The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the das...
CVE-2023-0948MEDIUM6.1The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in att...
CVE-2023-0894MEDIUM4.8The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settin...
CVE-2023-0768HIGH8.8The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortco...
CVE-2023-0603HIGH8.8The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is mis...
CVE-2023-0544MEDIUM4.8The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow hig...
CVE-2023-0542MEDIUM5.4The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode at...
CVE-2023-0537MEDIUM5.4The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcod...
CVE-2023-0536MEDIUM5.4The Wp-D3 WordPress plugin through 2.4.1 does not validate and escape some of its shortcode attributes before outputting...
CVE-2023-0526MEDIUM5.4The Post Shortcode WordPress plugin through 2.0.9 does not validate and escape some of its shortcode attributes before o...
CVE-2023-0522MEDIUM6.5The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updati...
CVE-2023-0514MEDIUM6.1The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back ...
CVE-2023-0421MEDIUM6.1The Cloud Manager WordPress plugin through 1.0 does not sanitise and escape the query param ricerca before outputting it...
CVE-2023-0280MEDIUM5.4The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block option...
CVE-2023-0268MEDIUM5.4The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortco...
CVE-2023-0267MEDIUM5.4The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its sh...
CVE-2023-2575HIGH8.8Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability,...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now