2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0630HIGH8.8The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that conca...
CVE-2023-0370MEDIUM5.4The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before...
CVE-2023-0369MEDIUM5.4The GoToWP WordPress plugin through 5.1.1 does not validate and escape some of its shortcode attributes before outputtin...
CVE-2023-0365MEDIUM5.4The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before out...
CVE-2023-0364MEDIUM5.4The real.Kit WordPress plugin before 5.1.1 does not validate and escape some of its shortcode attributes before outputti...
CVE-2023-0340HIGH8.8The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which coul...
CVE-2023-0273MEDIUM5.4The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attribute...
CVE-2023-0175MEDIUM5.4The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its s...
CVE-2023-0167MEDIUM5.4The GetResponse for WordPress plugin through 5.5.31 does not validate and escape some of its shortcode attributes before...
CVE-2023-0145MEDIUM5.4The Saan World Clock WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before o...
CVE-2023-28429MEDIUM6.1Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip f...
CVE-2023-28428LOW3.3PDFio is a C library for reading and writing PDF files. In versions 1.1.0 and prior, a denial of service vulnerability e...
CVE-2023-1515MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.
CVE-2023-28426Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: GHSA-xrqq-wqh4-5hg2. Reason: Further investigation showed...
CVE-2023-28424CRITICAL9.8Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and ...
CVE-2023-28118HIGH7.5kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untru...
CVE-2023-26513HIGH7.5Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache S...
CVE-2023-0320MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Izmir Katip Celebi...
CVE-2023-23721HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions.
CVE-2023-23718MEDIUM4.8Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Esstat17 Page Loading Effects plugin <= 2.0.0 versions.
CVE-2023-22682MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Manuel Masia | Pixedelic.Com Camera slideshow plugin <= 1.4.0.1 ve...
CVE-2023-22680MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Altanic No API Amazon Affiliate plugin <= 4.2.2 versio...
CVE-2023-22679MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nicolas Lemoine WP Better Emails plugin <= 0.4 version...
CVE-2023-22678HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Rafael Dery Superior FAQ plugin <= 1.0.2 versions.
CVE-2023-25795MEDIUM4.8Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now