2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4109 | MEDIUM | 4.8 | 0.4% | Aug 30, 2023 | The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection secur... |
| CVE-2023-4036 | MEDIUM | 4.3 | 0.5% | Aug 30, 2023 | The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public,... |
| CVE-2023-4035 | MEDIUM | 5.4 | 0.4% | Aug 30, 2023 | The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before o... |
| CVE-2023-4023 | MEDIUM | 4.3 | 0.4% | Aug 30, 2023 | The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages fr... |
| CVE-2023-4013 | MEDIUM | 6.5 | 0.3% | Aug 30, 2023 | The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks... |
| CVE-2023-3992 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | The PostX WordPress plugin before 3.0.6 does not sanitise and escape a parameter before outputting it back in the page, ... |
| CVE-2023-3720 | MEDIUM | 6.5 | 0.3% | Aug 30, 2023 | The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow a... |
| CVE-2023-3501 | MEDIUM | 4.8 | 0.4% | Aug 30, 2023 | The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-3356 | MEDIUM | 4.3 | 0.2% | Aug 30, 2023 | The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings,... |
| CVE-2023-34173 | MEDIUM | 4.8 | 0.4% | Aug 30, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Semikashev Yandex Metrica Counter plugin <= ... |
| CVE-2023-34172 | MEDIUM | 4.8 | 0.4% | Aug 30, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions. |
| CVE-2023-34032 | MEDIUM | 6.1 | 0.5% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions. |
| CVE-2023-34023 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions. |
| CVE-2023-34022 | MEDIUM | 6.1 | 0.5% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rakib Hasan Dynamic QR Code Generator plugin <= 0.0.5 vers... |
| CVE-2023-34008 | MEDIUM | 6.1 | 0.5% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in weDevs WP ERP plugin <= 1.12.3 versions. |
| CVE-2023-34004 | MEDIUM | 5.4 | 0.4% | Aug 30, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Box Office plugin <= 1.1... |
| CVE-2023-1982 | MEDIUM | 4.8 | 0.4% | Aug 30, 2023 | The Front Editor WordPress plugin through 4.0.4 does not sanitize and escape some of its form settings, which could allo... |
| CVE-2023-41538 | MEDIUM | 6.1 | 1.1% | Aug 30, 2023 | phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. |
| CVE-2023-41537 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. |
| CVE-2023-34187 | MEDIUM | 4.8 | 0.4% | Aug 30, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alan Tien Call Now Icon Animate plugin <= 0.1.0 versio... |
| CVE-2023-34184 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Bhavik Patel Woocommerce Order address Print plugin <= 3.2... |
| CVE-2023-34183 | MEDIUM | 4.8 | 0.4% | Aug 30, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Valiano Unite Gallery Lite plugin <= 1.7.61 versions. |
| CVE-2023-34180 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in KAPlugins Google Fonts For WordPress plugin <= 3.0.0 versi... |
| CVE-2023-34176 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chilexpress Chilexpress woo oficial plugin <= 1.2.9 versio... |
| CVE-2023-34175 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now