2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6369MEDIUM5.4The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification...
CVE-2023-6316CRITICAL9.8The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in ...
CVE-2023-6266HIGH7.5The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file...
CVE-2023-6220CRITICAL9.8The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation ...
CVE-2023-5691MEDIUM4.8The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio...
CVE-2023-5504HIGH8.7The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the L...
CVE-2023-52032CRITICAL9.8TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via th...
CVE-2023-52031CRITICAL9.8TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ...
CVE-2023-52030CRITICAL9.8TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ...
CVE-2023-52029CRITICAL9.8TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ...
CVE-2023-52028CRITICAL9.8TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ...
CVE-2023-52027CRITICAL9.8TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ...
CVE-2023-4962MEDIUM5.4The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in version...
CVE-2023-4960MEDIUM5.4The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in ve...
CVE-2023-4372MEDIUM5.4The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in version...
CVE-2023-4248MEDIUM4.3The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th...
CVE-2023-4247MEDIUM5.4The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th...
CVE-2023-4246MEDIUM4.3The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th...
CVE-2023-37644MEDIUM5.5SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstr...
CVE-2023-6883MEDIUM4.3The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-6699HIGH7.5The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions...
CVE-2023-6520MEDIUM4.3The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2023-6506MEDIUM4.3The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2023-6446MEDIUM4.8The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2023-6223MEDIUM4.3The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now