2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5070 | MEDIUM | 6.5 | 1.2% | Oct 20, 2023 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposu... |
| CVE-2023-4999 | HIGH | 8.8 | 0.7% | Oct 20, 2023 | The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-s... |
| CVE-2023-4961 | MEDIUM | 5.4 | 0.5% | Oct 20, 2023 | The Poptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'poptin-form' shortcode in versions up ... |
| CVE-2023-4941 | MEDIUM | 4.3 | 0.5% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ... |
| CVE-2023-4926 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4924 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ... |
| CVE-2023-4923 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4796 | MEDIUM | 4.3 | 0.6% | Oct 20, 2023 | The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in v... |
| CVE-2023-4668 | HIGH | 7.5 | 0.5% | Oct 20, 2023 | The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v... |
| CVE-2023-4648 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions... |
| CVE-2023-4386 | HIGH | 8.1 | 0.8% | Oct 20, 2023 | The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 ... |
| CVE-2023-4021 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The Modern Events Calendar lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google API key and... |
| CVE-2023-3998 | MEDIUM | 5.3 | 0.4% | Oct 20, 2023 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec... |
| CVE-2023-3996 | MEDIUM | 4.8 | 0.5% | Oct 20, 2023 | The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v... |
| CVE-2023-3869 | MEDIUM | 5.3 | 0.4% | Oct 20, 2023 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec... |
| CVE-2023-5576 | CRITICAL | 9.3 | 0.8% | Oct 20, 2023 | The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in version... |
| CVE-2023-5524 | HIGH | 7.3 | 0.3% | Oct 20, 2023 | Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before ... |
| CVE-2023-5523 | HIGH | 7.8 | 0.3% | Oct 20, 2023 | Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versi... |
| CVE-2023-5414 | HIGH | 7.2 | 1.0% | Oct 20, 2023 | The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 v... |
| CVE-2023-5308 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Podcast Subscribe Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'podcast_subscribe' ... |
| CVE-2023-5200 | MEDIUM | 5.4 | 0.5% | Oct 20, 2023 | The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up ... |
| CVE-2023-5120 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image... |
| CVE-2023-5071 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sitekit_iframe' shortcode in versions... |
| CVE-2023-5050 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ... |
| CVE-2023-4975 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now