2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1404MEDIUM5.4The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of ...
CVE-2023-1403MEDIUM5.4The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the p...
CVE-2023-1375MEDIUM4.3The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including,...
CVE-2023-1169MEDIUM4.3The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capabili...
CVE-2023-0993MEDIUM4.3The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action i...
CVE-2023-0992MEDIUM6.1The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, ...
CVE-2023-0832MEDIUM4.3The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including...
CVE-2023-0831MEDIUM4.3The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including...
CVE-2023-0729MEDIUM4.3The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2....
CVE-2023-0710MEDIUM5.4The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attr...
CVE-2023-0709MEDIUM5.4The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_nam...
CVE-2023-0708MEDIUM5.4The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_na...
CVE-2023-0695MEDIUM5.4The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortco...
CVE-2023-0694MEDIUM4.3The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode ...
CVE-2023-0693MEDIUM4.3The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction...
CVE-2023-0692MEDIUM4.3The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_sta...
CVE-2023-0691MEDIUM4.3The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' ...
CVE-2023-0688MEDIUM6.5The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' s...
CVE-2023-34243MEDIUM5.3TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgst...
CVE-2023-32751MEDIUM5.4Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera...
CVE-2023-32750MEDIUM6.5Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which ...
CVE-2023-29401MEDIUM4.3The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename ...
CVE-2023-34961MEDIUM6.1Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/co...
CVE-2023-34959MEDIUM5.3An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain i...
CVE-2023-34958MEDIUM4.3Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download docum...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now