2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5211MEDIUM6.1The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in ...
CVE-2023-5098HIGH8.1The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like s...
CVE-2023-4836MEDIUM4.3The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and...
CVE-2023-4823MEDIUM5.4The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings...
CVE-2023-4610Rejected reason: The SRCU code was added in upstream kernel v6.4-rc1 and removed before v6.4. This bug only existed in d...
CVE-2023-4390MEDIUM4.8The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privi...
CVE-2023-4251MEDIUM4.3The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attacke...
CVE-2023-4250MEDIUM6.1The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in...
CVE-2023-46979CRITICAL9.8TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parame...
CVE-2023-46978HIGH7.5TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WI...
CVE-2023-46977CRITICAL9.8TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the fu...
CVE-2023-46976CRITICAL9.8TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFil...
CVE-2023-28777HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDas...
CVE-2023-25047HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP...
CVE-2023-25045HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP...
CVE-2023-24000CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipres...
CVE-2023-5116MEDIUM5.4The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpul...
CVE-2023-5114MEDIUM5.4The idbbee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idbbee' shortcode in vers...
CVE-2023-5099HIGH8.8The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in...
CVE-2023-5073MEDIUM5.4The iframe forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'iframe' shortcode in version...
CVE-2023-38994HIGH7.8The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaint...
CVE-2023-46622MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.18.2 ve...
CVE-2023-46313MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.4 versions.
CVE-2023-46312MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 vers...
CVE-2023-40681MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11.10 version...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now