2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0955 | HIGH | 8.8 | 0.9% | Mar 27, 2023 | The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to per... |
| CVE-2023-0823 | MEDIUM | 5.4 | 0.5% | Mar 27, 2023 | The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.4.7 does not validate and escape some of its sh... |
| CVE-2023-0816 | MEDIUM | 6.5 | 0.5% | Mar 27, 2023 | The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address ... |
| CVE-2023-0660 | MEDIUM | 5.4 | 0.5% | Mar 27, 2023 | The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attribut... |
| CVE-2023-0589 | MEDIUM | 5.4 | 0.4% | Mar 27, 2023 | The WP Image Carousel WordPress plugin through 1.0.2 does not sanitise and escape some parameters, which could allow use... |
| CVE-2023-0505 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow atta... |
| CVE-2023-0504 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attacke... |
| CVE-2023-0503 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins... |
| CVE-2023-0502 | MEDIUM | 6.5 | 0.3% | Mar 27, 2023 | The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers... |
| CVE-2023-0501 | MEDIUM | 6.5 | 0.3% | Mar 27, 2023 | The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attac... |
| CVE-2023-0500 | MEDIUM | 6.5 | 0.3% | Mar 27, 2023 | The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow att... |
| CVE-2023-0499 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attacke... |
| CVE-2023-0498 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attac... |
| CVE-2023-0497 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attac... |
| CVE-2023-0496 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers... |
| CVE-2023-0495 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could ... |
| CVE-2023-0491 | MEDIUM | 5.4 | 0.6% | Mar 27, 2023 | The Schedulicity WordPress plugin through 2.21 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-0484 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF... |
| CVE-2023-0467 | MEDIUM | 4.3 | 0.7% | Mar 27, 2023 | The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using... |
| CVE-2023-0441 | HIGH | 8.1 | 0.7% | Mar 27, 2023 | The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenti... |
| CVE-2023-0395 | MEDIUM | 5.4 | 0.5% | Mar 27, 2023 | The menu shortcode WordPress plugin through 1.0 does not validate and escape some of its block options before outputting... |
| CVE-2023-0336 | MEDIUM | 6.5 | 1.0% | Mar 27, 2023 | The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities whic... |
| CVE-2023-0335 | MEDIUM | 6.5 | 1.0% | Mar 27, 2023 | The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with ro... |
| CVE-2023-0272 | MEDIUM | 5.4 | 0.5% | Mar 27, 2023 | The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2023-27296 | HIGH | 8.8 | 1.5% | Mar 27, 2023 | Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now