2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-4836MEDIUM4.3The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and...
CVE-2023-4823MEDIUM5.4The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings...
CVE-2023-4390MEDIUM4.8The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privi...
CVE-2023-4251MEDIUM4.3The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attacke...
CVE-2023-4250MEDIUM6.1The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in...
CVE-2023-5116MEDIUM5.4The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpul...
CVE-2023-5114MEDIUM5.4The idbbee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idbbee' shortcode in vers...
CVE-2023-5073MEDIUM5.4The iframe forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'iframe' shortcode in version...
CVE-2023-46622MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.18.2 ve...
CVE-2023-46313MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.4 versions.
CVE-2023-46312MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 vers...
CVE-2023-40681MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11.10 version...
CVE-2023-5873MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.
CVE-2023-5464MEDIUM6.5The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in version...
CVE-2023-5439MEDIUM6.5The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u...
CVE-2023-5438MEDIUM6.5The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,...
CVE-2023-5437MEDIUM6.5The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up t...
CVE-2023-5436MEDIUM6.5The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a...
CVE-2023-5435MEDIUM6.5The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in ve...
CVE-2023-5434MEDIUM6.5The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions ...
CVE-2023-5433MEDIUM6.5The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and...
CVE-2023-5431MEDIUM6.5The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in...
CVE-2023-5430MEDIUM6.5The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,...
CVE-2023-5429MEDIUM6.5The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a...
CVE-2023-5428MEDIUM6.5The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now