2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2811MEDIUM4.8The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow hi...
CVE-2023-2805HIGH7.2The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_a...
CVE-2023-2779MEDIUM6.1The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parame...
CVE-2023-2751MEDIUM5.3The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the...
CVE-2023-2742MEDIUM4.8The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users su...
CVE-2023-2719HIGH8.8The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in ...
CVE-2023-2684MEDIUM4.8The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could...
CVE-2023-2654MEDIUM6.1The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribut...
CVE-2023-2600MEDIUM4.8The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow...
CVE-2023-2527MEDIUM4.8The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and esca...
CVE-2023-2492HIGH7.2The QueryWall: Plug'n Play Firewall WordPress plugin through 1.1.1 does not properly sanitise and escape a parameter bef...
CVE-2023-2401MEDIUM4.8The QuBot WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2023-2399MEDIUM6.1The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflect...
CVE-2023-2359HIGH8.8The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an ar...
CVE-2023-2221HIGH7.2The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a...
CVE-2023-29546MEDIUM6.5When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden,...
CVE-2023-29545MEDIUM6.5Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable n...
CVE-2023-29542CRITICAL9.8A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious fil...
CVE-2023-29534CRITICAL9.1Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have ...
CVE-2023-25747HIGH7.5A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below versi...
CVE-2023-25736CRITICAL9.8An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affe...
CVE-2023-25733HIGH7.5The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null ...
CVE-2023-0489MEDIUM5.4The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0368MEDIUM5.4The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate ...
CVE-2023-32216CRITICAL9.8Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team repo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now