2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3962MEDIUM6.1The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up t...
CVE-2023-3933MEDIUM6.1The Your Journey theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions...
CVE-2023-46287MEDIUM6.1XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.
CVE-2023-5618MEDIUM5.4The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ver...
CVE-2023-44483MEDIUM6.5All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, a...
CVE-2023-44256MEDIUM6.5A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2...
CVE-2023-34044MEDIUM6VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that...
CVE-2023-5615MEDIUM5.4The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-statu...
CVE-2023-5534MEDIUM5.4The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 ...
CVE-2023-5337MEDIUM5.4The Contact form Form For All plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortco...
CVE-2023-5292MEDIUM5.4The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acfe_for...
CVE-2023-5231MEDIUM5.4The Magic Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,...
CVE-2023-5121MEDIUM4.8The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set...
CVE-2023-5109MEDIUM5.4The WP Mailto Links – Protect Email Addresses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wpm...
CVE-2023-5086MEDIUM5.4The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'copy' shortcode in...
CVE-2023-5070MEDIUM6.5The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2023-4961MEDIUM5.4The Poptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'poptin-form' shortcode in versions up ...
CVE-2023-4941MEDIUM4.3The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ...
CVE-2023-4926MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4924MEDIUM4.3The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ...
CVE-2023-4923MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4796MEDIUM4.3The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in v...
CVE-2023-4648MEDIUM4.8The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions...
CVE-2023-4021MEDIUM4.8The Modern Events Calendar lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google API key and...
CVE-2023-3998MEDIUM5.3The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now