2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-53915 | MEDIUM | 4.6 | 0.3% | Dec 17, 2025 | Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject maliciou... |
| CVE-2023-53911 | MEDIUM | 5.4 | 0.3% | Dec 17, 2025 | Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows auth... |
| CVE-2023-53910 | MEDIUM | 5.4 | 0.3% | Dec 17, 2025 | WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malici... |
| CVE-2023-53909 | MEDIUM | 5.4 | 0.3% | Dec 17, 2025 | WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malici... |
| CVE-2023-53906 | MEDIUM | 4.8 | 0.3% | Dec 17, 2025 | projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to injec... |
| CVE-2023-53904 | MEDIUM | 5.1 | 0.2% | Dec 17, 2025 | Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject m... |
| CVE-2023-53900 | MEDIUM | 6.1 | 0.3% | Dec 16, 2025 | Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded exter... |
| CVE-2023-53903 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malic... |
| CVE-2023-53901 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to c... |
| CVE-2023-53898 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject ma... |
| CVE-2023-53897 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to in... |
| CVE-2023-53893 | MEDIUM | 6.5 | 0.2% | Dec 15, 2025 | Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL pa... |
| CVE-2023-53891 | MEDIUM | 5.4 | 0.2% | Dec 15, 2025 | Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject maliciou... |
| CVE-2023-53890 | MEDIUM | 5.4 | 0.2% | Dec 15, 2025 | Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious S... |
| CVE-2023-53887 | MEDIUM | 5.4 | 0.2% | Dec 15, 2025 | Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts wh... |
| CVE-2023-53884 | MEDIUM | 5.4 | 0.2% | Dec 15, 2025 | Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload m... |
| CVE-2023-53882 | MEDIUM | 5.1 | 0.3% | Dec 15, 2025 | JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attack... |
| CVE-2023-53880 | MEDIUM | 4.8 | 0.3% | Dec 15, 2025 | Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject mal... |
| CVE-2023-53879 | MEDIUM | 5.5 | 0.2% | Dec 15, 2025 | NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attacker... |
| CVE-2023-53878 | MEDIUM | 6.9 | 0.3% | Dec 15, 2025 | Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP ... |
| CVE-2023-53876 | MEDIUM | 5.4 | 0.2% | Dec 15, 2025 | Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with ... |
| CVE-2023-53870 | MEDIUM | 5.1 | 0.3% | Dec 15, 2025 | Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to ... |
| CVE-2023-38913 | MEDIUM | 5.3 | 0.5% | Dec 15, 2025 | SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a cr... |
| CVE-2023-36338 | MEDIUM | 5.3 | 0.3% | Dec 15, 2025 | Inventory Management System 1 was discovered to contain a SQL injection vulnerability. |
| CVE-2023-36337 | MEDIUM | 6.1 | 0.2% | Dec 15, 2025 | A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management Syste... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now