2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3996 | MEDIUM | 4.8 | 0.5% | Oct 20, 2023 | The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v... |
| CVE-2023-3869 | MEDIUM | 5.3 | 0.4% | Oct 20, 2023 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec... |
| CVE-2023-5308 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Podcast Subscribe Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'podcast_subscribe' ... |
| CVE-2023-5200 | MEDIUM | 5.4 | 0.5% | Oct 20, 2023 | The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up ... |
| CVE-2023-5120 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image... |
| CVE-2023-5071 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sitekit_iframe' shortcode in versions... |
| CVE-2023-5050 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ... |
| CVE-2023-4975 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and ... |
| CVE-2023-4968 | MEDIUM | 4.8 | 0.4% | Oct 20, 2023 | The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versio... |
| CVE-2023-4947 | MEDIUM | 4.3 | 0.4% | Oct 20, 2023 | The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2023-4943 | MEDIUM | 4.3 | 0.5% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ... |
| CVE-2023-4942 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4940 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4937 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4935 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4919 | MEDIUM | 5.4 | 0.5% | Oct 20, 2023 | The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `iframe` shortcode in versions up t... |
| CVE-2023-4598 | MEDIUM | 6.5 | 0.9% | Oct 20, 2023 | The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,... |
| CVE-2023-4482 | MEDIUM | 5.4 | 0.3% | Oct 20, 2023 | The Auto Amazon Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in versi... |
| CVE-2023-4274 | MEDIUM | 6.5 | 1.2% | Oct 20, 2023 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, an... |
| CVE-2023-4271 | MEDIUM | 4.8 | 0.4% | Oct 20, 2023 | The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘psres_button_size’ ... |
| CVE-2023-2325 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS S... |
| CVE-2023-5668 | MEDIUM | 5.4 | 0.3% | Oct 20, 2023 | The WhatsApp Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'whatsapp' ... |
| CVE-2023-5614 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list... |
| CVE-2023-5613 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' sho... |
| CVE-2023-45471 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now