CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2023-6037

    Last Modified: 18 Jun 2025

    The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 1 Jan 2024
    6.1
    Medium

    CVE-2023-6000

    Last Modified: 18 Jun 2025

    The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

    Published: 1 Jan 2024
    5.4
    Medium

    CVE-2023-6485

    Last Modified: 18 Jun 2025

    The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

    Published: 1 Jan 2024
    7.5
    High

    CVE-2023-6271

    Last Modified: 11 Jun 2025

    The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.

    Published: 1 Jan 2024
    7.5
    High

    CVE-2023-6421

    Last Modified: 18 Jun 2025

    The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

    Published: 1 Jan 2024
    7.5
    High

    CVE-2023-6064

    Last Modified: 9 Jan 2026

    The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.

    Published: 1 Jan 2024
    2.4
    Low

    CVE-2024-0181

    Last Modified: 3 Jun 2025

    A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin_user.php of the component Admin Panel. The manipulation of the argument Firstname/Lastname/Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249433 was assigned to this vulnerability.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21721

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21720

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21712

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21713

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21714

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21715

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21716

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21717

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21718

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21719

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21709

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21702

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21704

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21705

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21708

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21710

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21711

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21694

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21695

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21696

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21693

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21701

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21692

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21688

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21691

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21675

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    —
    Unknown

    CVE-2024-21679

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2024
    7.5
    High

    CVE-2023-50096

    Last Modified: 21 Nov 2024

    STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.

    Published: 1 Jan 2024
    8.8
    High

    CVE-2023-50094

    Last Modified: 17 Apr 2025

    reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.

    Published: 1 Jan 2024
    6.1
    Medium

    CVE-2024-21732

    Last Modified: 3 Jun 2025

    FlyCms through abbaa5a allows XSS via the permission management feature.

    Published: 1 Jan 2024
    5.9
    Medium

    CVE-2023-51503

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.

    Published: 31 Dec 2023
    9.3
    Critical

    CVE-2023-51423

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through 3.05.0.

    Published: 31 Dec 2023
    9.3
    Critical

    CVE-2023-51469

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Checkout Mestres WP.This issue affects Checkout Mestres WP: from n/a through 7.1.9.6.

    Published: 31 Dec 2023
    7.6
    High

    CVE-2023-52131

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Zinc Page Generator.This issue affects Page Generator: from n/a through 1.7.1.

    Published: 31 Dec 2023
    7.6
    High

    CVE-2023-51547

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin.This issue affects Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin: from n/a through 1.7.6.

    Published: 31 Dec 2023
    7.6
    High

    CVE-2023-52132

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jewel Theme WP Adminify.This issue affects WP Adminify: from n/a through 3.1.6.

    Published: 31 Dec 2023
    8.5
    High

    CVE-2023-52133

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhileTrue Most And Least Read Posts Widget.This issue affects Most And Least Read Posts Widget: from n/a through 2.5.16.

    Published: 31 Dec 2023
    7.6
    High

    CVE-2023-52134

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2.

    Published: 31 Dec 2023
    5.3
    Medium

    CVE-2023-52185

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin.This issue affects Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin: from n/a through 2.1.9.

    Published: 31 Dec 2023
    4.6
    Medium

    CVE-2023-7193

    Last Modified: 21 Nov 2024

    A vulnerability was found in MTab Bookmark up to 1.2.6 and classified as critical. This issue affects some unknown processing of the file public/install.php of the component Installation. The manipulation leads to improper access controls. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249395. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-7191

    Last Modified: 17 Apr 2025

    A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an unknown part of the file member/reg.php. The manipulation of the argument M_login/M_email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249393 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-7190

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by this issue is some unknown functionality of the file /member/ad.php?action=ad. The manipulation of the argument A_text/A_url/A_contact leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-7189

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006. Affected by this vulnerability is an unknown functionality of the file /s/index.php?action=statistics. The manipulation of the argument lid leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249391. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023