2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3996MEDIUM4.8The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v...
CVE-2023-3869MEDIUM5.3The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec...
CVE-2023-5308MEDIUM5.4The Podcast Subscribe Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'podcast_subscribe' ...
CVE-2023-5200MEDIUM5.4The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up ...
CVE-2023-5120MEDIUM4.8The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image...
CVE-2023-5071MEDIUM5.4The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sitekit_iframe' shortcode in versions...
CVE-2023-5050MEDIUM5.4The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ...
CVE-2023-4975MEDIUM4.3The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and ...
CVE-2023-4968MEDIUM4.8The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versio...
CVE-2023-4947MEDIUM4.3The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2023-4943MEDIUM4.3The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ...
CVE-2023-4942MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4940MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4937MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4935MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4919MEDIUM5.4The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `iframe` shortcode in versions up t...
CVE-2023-4598MEDIUM6.5The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,...
CVE-2023-4482MEDIUM5.4The Auto Amazon Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in versi...
CVE-2023-4274MEDIUM6.5The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, an...
CVE-2023-4271MEDIUM4.8The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘psres_button_size’ ...
CVE-2023-2325MEDIUM5.4Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS S...
CVE-2023-5668MEDIUM5.4The WhatsApp Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'whatsapp' ...
CVE-2023-5614MEDIUM5.4The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list...
CVE-2023-5613MEDIUM5.4The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' sho...
CVE-2023-45471MEDIUM5.4The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now