2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6164 | MEDIUM | 4.8 | 0.4% | Nov 22, 2023 | The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS In... |
| CVE-2023-6160 | MEDIUM | 6.7 | 0.8% | Nov 22, 2023 | The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions... |
| CVE-2023-6009 | HIGH | 8.8 | 0.9% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to in... |
| CVE-2023-6008 | MEDIUM | 4.3 | 0.2% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th... |
| CVE-2023-6007 | MEDIUM | 6.5 | 0.3% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to... |
| CVE-2023-5822 | CRITICAL | 9.8 | 1.8% | Nov 22, 2023 | The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due... |
| CVE-2023-5815 | CRITICAL | 9.8 | 4.3% | Nov 22, 2023 | The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post... |
| CVE-2023-5742 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | The EasyRotator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyro... |
| CVE-2023-5715 | MEDIUM | 4.8 | 0.5% | Nov 22, 2023 | The Website Optimization – Plerdy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tra... |
| CVE-2023-5708 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | The WP Post Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'column' shortcod... |
| CVE-2023-5706 | MEDIUM | 5.4 | 0.5% | Nov 22, 2023 | The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk-blocks/ancestor-pag... |
| CVE-2023-5704 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all ... |
| CVE-2023-5667 | MEDIUM | 5.4 | 0.5% | Nov 22, 2023 | The Tab Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all ve... |
| CVE-2023-5664 | MEDIUM | 5.4 | 0.6% | Nov 22, 2023 | The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ggpkg' shor... |
| CVE-2023-5662 | MEDIUM | 5.4 | 0.5% | Nov 22, 2023 | The Sponsors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sponsors' shortcode in ... |
| CVE-2023-5537 | MEDIUM | 4.3 | 0.3% | Nov 22, 2023 | The Delete Usermeta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1... |
| CVE-2023-5469 | MEDIUM | 5.4 | 0.5% | Nov 22, 2023 | The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in... |
| CVE-2023-5466 | HIGH | 8.8 | 0.8% | Nov 22, 2023 | The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,... |
| CVE-2023-5465 | HIGH | 8.8 | 0.8% | Nov 22, 2023 | The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to... |
| CVE-2023-5419 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2023-5417 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2023-5416 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2023-5415 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2023-5411 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2023-5387 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now