2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0955HIGH8.8The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to per...
CVE-2023-0823MEDIUM5.4The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.4.7 does not validate and escape some of its sh...
CVE-2023-0816MEDIUM6.5The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address ...
CVE-2023-0660MEDIUM5.4The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attribut...
CVE-2023-0589MEDIUM5.4The WP Image Carousel WordPress plugin through 1.0.2 does not sanitise and escape some parameters, which could allow use...
CVE-2023-0505MEDIUM4.3The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow atta...
CVE-2023-0504MEDIUM4.3The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attacke...
CVE-2023-0503MEDIUM4.3The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins...
CVE-2023-0502MEDIUM6.5The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers...
CVE-2023-0501MEDIUM6.5The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attac...
CVE-2023-0500MEDIUM6.5The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow att...
CVE-2023-0499MEDIUM4.3The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attacke...
CVE-2023-0498MEDIUM4.3The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attac...
CVE-2023-0497MEDIUM4.3The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attac...
CVE-2023-0496MEDIUM4.3The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers...
CVE-2023-0495MEDIUM4.3The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could ...
CVE-2023-0491MEDIUM5.4The Schedulicity WordPress plugin through 2.21 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0484MEDIUM4.3The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF...
CVE-2023-0467MEDIUM4.3The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using...
CVE-2023-0441HIGH8.1The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenti...
CVE-2023-0395MEDIUM5.4The menu shortcode WordPress plugin through 1.0 does not validate and escape some of its block options before outputting...
CVE-2023-0336MEDIUM6.5The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities whic...
CVE-2023-0335MEDIUM6.5The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with ro...
CVE-2023-0272MEDIUM5.4The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-27296HIGH8.8Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now