2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5386MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-5385MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-5383MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2023-5382MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2023-5338MEDIUM5.4The Theme Blvd Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u...
CVE-2023-5314MEDIUM4.3The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capa...
CVE-2023-5234MEDIUM5.4The Related Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'woo-related'...
CVE-2023-5163MEDIUM5.4The Weather Atlas Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortcode-weather-atlas'...
CVE-2023-5128MEDIUM5.4The TCD Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'map' shortcode in versions up...
CVE-2023-5096MEDIUM5.4The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '...
CVE-2023-5048MEDIUM5.4The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder...
CVE-2023-4726MEDIUM4.8The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions ...
CVE-2023-4686MEDIUM4.3The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl...
CVE-2023-48705MEDIUM5.4Nautobot is a Network Source of Truth and Network Automation Platform built as a web application All users of Nautobot v...
CVE-2023-47350HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote a...
CVE-2023-2841HIGH7.2The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id para...
CVE-2023-2497HIGH8.8The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th...
CVE-2023-2449CRITICAL9.8The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. T...
CVE-2023-2448MEDIUM5.3The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2023-2440HIGH8.8The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th...
CVE-2023-2438MEDIUM6.1The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th...
CVE-2023-2437HIGH8.1The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is...
CVE-2023-47380MEDIUM6.1Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS).
CVE-2023-26542HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Exeebit phpinfo() WP plugin <= 4.0 versions.
CVE-2023-6252HIGH7.5Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now