2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0542MEDIUM5.4The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode at...
CVE-2023-0537MEDIUM5.4The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcod...
CVE-2023-0536MEDIUM5.4The Wp-D3 WordPress plugin through 2.4.1 does not validate and escape some of its shortcode attributes before outputting...
CVE-2023-0526MEDIUM5.4The Post Shortcode WordPress plugin through 2.0.9 does not validate and escape some of its shortcode attributes before o...
CVE-2023-0522MEDIUM6.5The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updati...
CVE-2023-0514MEDIUM6.1The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back ...
CVE-2023-0421MEDIUM6.1The Cloud Manager WordPress plugin through 1.0 does not sanitise and escape the query param ricerca before outputting it...
CVE-2023-0280MEDIUM5.4The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block option...
CVE-2023-0268MEDIUM5.4The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortco...
CVE-2023-0267MEDIUM5.4The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its sh...
CVE-2023-28169MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 version...
CVE-2023-25452MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Pretty (prettyboymp) CMS Press plugin <= 0.2.3...
CVE-2023-25052MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa Yandex.News Feed by Teplitsa plugin <= 1.12.5...
CVE-2023-25021MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FareHarbor FareHarbor for WordPress plugin <= 3.6.6 ve...
CVE-2023-23668MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP plugin <= 2.25.1 versions.
CVE-2023-29247MEDIUM5.4Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.
CVE-2023-2566MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2565MEDIUM6.1A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problema...
CVE-2023-24400MEDIUM5.4Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Hu-manity.Co Cookie Notice & Compliance for GDPR / CCPA...
CVE-2023-25491MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Samuel Marshall JCH Optimize plugin <= 3.2.2 versions.
CVE-2023-2560MEDIUM6.1A vulnerability was found in jja8 NewBingGoGo up to 2023.5.5.2. It has been rated as problematic. This issue affects som...
CVE-2023-26519MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.5.4 versi...
CVE-2023-26517MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 ver...
CVE-2023-24957MEDIUM5.4IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2,...
CVE-2023-29354MEDIUM4.7Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now