2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5070MEDIUM6.5The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2023-4999HIGH8.8The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-s...
CVE-2023-4961MEDIUM5.4The Poptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'poptin-form' shortcode in versions up ...
CVE-2023-4941MEDIUM4.3The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ...
CVE-2023-4926MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4924MEDIUM4.3The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ...
CVE-2023-4923MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4796MEDIUM4.3The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in v...
CVE-2023-4668HIGH7.5The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v...
CVE-2023-4648MEDIUM4.8The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions...
CVE-2023-4386HIGH8.1The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 ...
CVE-2023-4021MEDIUM4.8The Modern Events Calendar lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google API key and...
CVE-2023-3998MEDIUM5.3The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec...
CVE-2023-3996MEDIUM4.8The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v...
CVE-2023-3869MEDIUM5.3The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec...
CVE-2023-5576CRITICAL9.3The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in version...
CVE-2023-5524HIGH7.3Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before ...
CVE-2023-5523HIGH7.8Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versi...
CVE-2023-5414HIGH7.2The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 v...
CVE-2023-5308MEDIUM5.4The Podcast Subscribe Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'podcast_subscribe' ...
CVE-2023-5200MEDIUM5.4The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up ...
CVE-2023-5120MEDIUM4.8The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image...
CVE-2023-5071MEDIUM5.4The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sitekit_iframe' shortcode in versions...
CVE-2023-5050MEDIUM5.4The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ...
CVE-2023-4975MEDIUM4.3The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now