CVE-2023-6037
Last Modified: 18 Jun 2025The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2023-6000
Last Modified: 18 Jun 2025The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
CVE-2023-6485
Last Modified: 18 Jun 2025The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins
CVE-2023-6271
Last Modified: 11 Jun 2025The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.
CVE-2023-6421
Last Modified: 18 Jun 2025The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
CVE-2023-6064
Last Modified: 9 Jan 2026The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.
CVE-2024-0181
Last Modified: 3 Jun 2025A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin_user.php of the component Admin Panel. The manipulation of the argument Firstname/Lastname/Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249433 was assigned to this vulnerability.
CVE-2024-21721
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21720
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21712
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21713
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21714
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21715
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21716
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21717
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21718
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21719
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21709
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21702
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21704
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21705
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21708
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21710
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21711
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21694
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21695
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21696
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21693
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21701
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21692
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21688
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21691
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21675
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-21679
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2023-50096
Last Modified: 21 Nov 2024STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.
CVE-2023-50094
Last Modified: 17 Apr 2025reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.
CVE-2024-21732
Last Modified: 3 Jun 2025FlyCms through abbaa5a allows XSS via the permission management feature.
CVE-2023-51503
Last Modified: 28 Apr 2026Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.
CVE-2023-51423
Last Modified: 28 Apr 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through 3.05.0.
CVE-2023-51469
Last Modified: 28 Apr 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Checkout Mestres WP.This issue affects Checkout Mestres WP: from n/a through 7.1.9.6.
CVE-2023-52131
Last Modified: 28 Apr 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Zinc Page Generator.This issue affects Page Generator: from n/a through 1.7.1.
CVE-2023-51547
Last Modified: 28 Apr 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin.This issue affects Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin: from n/a through 1.7.6.
CVE-2023-52132
Last Modified: 28 Apr 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jewel Theme WP Adminify.This issue affects WP Adminify: from n/a through 3.1.6.
CVE-2023-52133
Last Modified: 28 Apr 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhileTrue Most And Least Read Posts Widget.This issue affects Most And Least Read Posts Widget: from n/a through 2.5.16.
CVE-2023-52134
Last Modified: 28 Apr 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2.
CVE-2023-52185
Last Modified: 28 Apr 2026Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin.This issue affects Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin: from n/a through 2.1.9.
CVE-2023-7193
Last Modified: 21 Nov 2024A vulnerability was found in MTab Bookmark up to 1.2.6 and classified as critical. This issue affects some unknown processing of the file public/install.php of the component Installation. The manipulation leads to improper access controls. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249395. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-7191
Last Modified: 17 Apr 2025A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an unknown part of the file member/reg.php. The manipulation of the argument M_login/M_email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249393 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-7190
Last Modified: 21 Nov 2024A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by this issue is some unknown functionality of the file /member/ad.php?action=ad. The manipulation of the argument A_text/A_url/A_contact leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-7189
Last Modified: 21 Nov 2024A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006. Affected by this vulnerability is an unknown functionality of the file /s/index.php?action=statistics. The manipulation of the argument lid leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249391. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
