2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4836 | MEDIUM | 4.3 | 0.5% | Oct 31, 2023 | The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and... |
| CVE-2023-4823 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings... |
| CVE-2023-4390 | MEDIUM | 4.8 | 0.4% | Oct 31, 2023 | The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privi... |
| CVE-2023-4251 | MEDIUM | 4.3 | 0.2% | Oct 31, 2023 | The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attacke... |
| CVE-2023-4250 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in... |
| CVE-2023-5116 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpul... |
| CVE-2023-5114 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The idbbee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idbbee' shortcode in vers... |
| CVE-2023-5073 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The iframe forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'iframe' shortcode in version... |
| CVE-2023-46622 | MEDIUM | 6.1 | 0.3% | Oct 31, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.18.2 ve... |
| CVE-2023-46313 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.4 versions. |
| CVE-2023-46312 | MEDIUM | 6.1 | 0.3% | Oct 31, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 vers... |
| CVE-2023-40681 | MEDIUM | 4.8 | 0.3% | Oct 31, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11.10 version... |
| CVE-2023-5873 | MEDIUM | 5.4 | 0.3% | Oct 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0. |
| CVE-2023-5464 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in version... |
| CVE-2023-5439 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u... |
| CVE-2023-5438 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,... |
| CVE-2023-5437 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up t... |
| CVE-2023-5436 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a... |
| CVE-2023-5435 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in ve... |
| CVE-2023-5434 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions ... |
| CVE-2023-5433 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and... |
| CVE-2023-5431 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in... |
| CVE-2023-5430 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,... |
| CVE-2023-5429 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a... |
| CVE-2023-5428 | MEDIUM | 6.5 | 0.8% | Oct 31, 2023 | The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now