CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-23393

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23394

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23395

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23396

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23397

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23398

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23392

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23389

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23390

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23391

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    6.3
    Medium

    CVE-2024-0601

    Last Modified: 17 Jun 2025

    A vulnerability was found in ZhongFuCheng3y Austin 1.0. It has been rated as critical. Affected by this issue is the function getRemoteUrl2File of the file src\main\java\com\java3y\austin\support\utils\AustinFileUtils.java of the component Email Message Template Handler. The manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250838 is the identifier assigned to this vulnerability.

    Published: 16 Jan 2024
    8.8
    High

    CVE-2024-0517

    Last Modified: 22 May 2025

    Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 16 Jan 2024
    3.5
    Low

    CVE-2024-0599

    Last Modified: 9 May 2025

    A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src\main\java\com\jspxcms\core\web\back\InfoController.java of the component Document Management Page. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250837 was assigned to this vulnerability.

    Published: 16 Jan 2024
    5.6
    Medium

    CVE-2023-37522

    Last Modified: 16 Jun 2025

    HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.

    Published: 16 Jan 2024
    6.1
    Medium

    CVE-2023-7151

    Last Modified: 27 Feb 2026

    The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 16 Jan 2024
    8.8
    High

    CVE-2023-6373

    Last Modified: 11 Jun 2025

    The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)

    Published: 16 Jan 2024
    4.3
    Medium

    CVE-2023-6292

    Last Modified: 2 Jun 2025

    The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-5922

    Last Modified: 2 Jun 2025

    The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private and password protected posts/pages content

    Published: 16 Jan 2024
    4.3
    Medium

    CVE-2023-7125

    Last Modified: 17 Jun 2025

    The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack

    Published: 16 Jan 2024
    5.4
    Medium

    CVE-2023-7083

    Last Modified: 2 Jun 2025

    The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 16 Jan 2024
    6.1
    Medium

    CVE-2024-0239

    Last Modified: 9 Jan 2026

    The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.

    Published: 16 Jan 2024
    5.4
    Medium

    CVE-2023-7084

    Last Modified: 20 Jun 2025

    The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS attacks

    Published: 16 Jan 2024
    4.8
    Medium

    CVE-2023-7154

    Last Modified: 21 Nov 2024

    The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 16 Jan 2024
    4.8
    Medium

    CVE-2023-6732

    Last Modified: 2 Jun 2025

    The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 16 Jan 2024
    4.8
    Medium

    CVE-2023-6005

    Last Modified: 20 Jun 2025

    The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 16 Jan 2024
    5.3
    Medium

    CVE-2023-6592

    Last Modified: 20 Jun 2025

    The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

    Published: 16 Jan 2024
    6.5
    Medium

    CVE-2023-6824

    Last Modified: 11 Jun 2025

    The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.

    Published: 16 Jan 2024
    4.3
    Medium

    CVE-2023-6741

    Last Modified: 20 Jun 2025

    The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-4703

    Last Modified: 20 Jun 2025

    The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

    Published: 16 Jan 2024
    7.2
    High

    CVE-2023-4797

    Last Modified: 11 Jun 2025

    The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

    Published: 16 Jan 2024
    5.4
    Medium

    CVE-2023-4757

    Last Modified: 20 Jun 2025

    The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

    Published: 16 Jan 2024
    8.8
    High

    CVE-2023-4536

    Last Modified: 20 Jun 2025

    The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

    Published: 16 Jan 2024
    6.5
    Medium

    CVE-2023-0824

    Last Modified: 20 Jun 2025

    The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

    Published: 16 Jan 2024
    6.1
    Medium

    CVE-2023-0769

    Last Modified: 2 Jun 2025

    The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-1405

    Last Modified: 11 Jun 2025

    The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

    Published: 16 Jan 2024
    4.8
    Medium

    CVE-2023-0389

    Last Modified: 11 Jun 2025

    The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 16 Jan 2024
    5.4
    Medium

    CVE-2023-0376

    Last Modified: 2 Jun 2025

    The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 16 Jan 2024
    5.4
    Medium

    CVE-2023-0094

    Last Modified: 9 Jan 2026

    The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 16 Jan 2024
    2.7
    Low

    CVE-2023-2252

    Last Modified: 2 Jun 2025

    The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

    Published: 16 Jan 2024
    5.4
    Medium

    CVE-2023-3372

    Last Modified: 20 Jun 2025

    The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 16 Jan 2024
    4.3
    Medium

    CVE-2023-3178

    Last Modified: 2 Jun 2025

    The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.

    Published: 16 Jan 2024
    2.3
    Low

    CVE-2023-37521

    Last Modified: 21 Nov 2024

    HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.

    Published: 16 Jan 2024
    7.2
    High

    CVE-2023-2655

    Last Modified: 2 Jun 2025

    The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

    Published: 16 Jan 2024
    6.1
    Medium

    CVE-2023-0479

    Last Modified: 20 Jun 2025

    The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.

    Published: 16 Jan 2024
    5.4
    Medium

    CVE-2023-0079

    Last Modified: 2 Jun 2025

    The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 16 Jan 2024
    9.8
    Critical

    CVE-2023-0224

    Last Modified: 13 Jun 2025

    The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks

    Published: 16 Jan 2024
    6.1
    Medium

    CVE-2023-5558

    Last Modified: 21 Nov 2024

    The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 16 Jan 2024
    4.8
    Medium

    CVE-2023-6046

    Last Modified: 13 Jun 2025

    The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.

    Published: 16 Jan 2024
    6.1
    Medium

    CVE-2023-3771

    Last Modified: 20 Jun 2025

    The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

    Published: 16 Jan 2024
    9.8
    Critical

    CVE-2023-3211

    Last Modified: 11 Jun 2025

    The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

    Published: 16 Jan 2024