CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2023-47558

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mahlamusa Who Hit The Page – Hit Counter allows SQL Injection.This issue affects Who Hit The Page – Hit Counter: from n/a through 1.4.14.3.

    Published: 18 Dec 2023
    8.5
    High

    CVE-2023-33331

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.

    Published: 18 Dec 2023
    7.6
    High

    CVE-2023-34168

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Raven WP Report Post allows SQL Injection.This issue affects WP Report Post: from n/a through 2.1.2.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49821

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-49763

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Creatomatic Ltd CSprite.This issue affects CSprite: from n/a through 1.1.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49761

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49760

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49759

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49163

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.5.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-49155

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-49153

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam Add to Cart Text Changer and Customize Button, Add Custom Icon.This issue affects Add to Cart Text Changer and Customize Button, Add Custom Icon: from n/a through 2.0.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49148

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kulwant Nagi Affiliate Booster – Pros & Cons, Notice, and CTA Blocks for Affiliates.This issue affects Affiliate Booster – Pros & Cons, Notice, and CTA Blocks for Affiliates: from n/a through 3.0.5.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-48781

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-48778

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Product Size Chart For WooCommerce.This issue affects Product Size Chart For WooCommerce: from n/a through 1.1.5.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-48773

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect.This issue affects WooCommerce Login Redirect: from n/a through 2.2.4.

    Published: 18 Dec 2023
    5.5
    Medium

    CVE-2023-46686

    Last Modified: 21 Nov 2024

    A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).

    Published: 18 Dec 2023
    2.4
    Low

    CVE-2023-41967

    Last Modified: 21 Nov 2024

    Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages. This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier.

    Published: 18 Dec 2023
    7.5
    High

    CVE-2023-24590

    Last Modified: 21 Nov 2024

    A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-23584

    Last Modified: 21 Nov 2024

    An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior to vEL8.60.2039 (MR4), all version of 8.50 and prior.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-23576

    Last Modified: 21 Nov 2024

    Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network outage when competencies are used in the access decision. This issue affects: Gallagher Command Centre: 8.90 prior to vEL8.90.1620 (MR2), 8.80 prior to vEL8.80.1369 (MR3), 8.70 prior to vEL8.70.2375 (MR5), 8.60 prior to vEL8.60.2550 (MR7), all versions of 8.50 and prior.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-23570

    Last Modified: 27 Nov 2024

    Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Gallagher Command Centre 8.90 prior to vEL8.90.1620 (MR2), all versions of 8.80 and prior.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-48772

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation: from n/a through 2.0.

    Published: 18 Dec 2023
    3.1
    Low

    CVE-2023-22439

    Last Modified: 21 Nov 2024

    Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-48769

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Blue Coral Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back.This issue affects Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back: from n/a through 2.3.

    Published: 18 Dec 2023
    6.8
    Medium

    CVE-2023-6355

    Last Modified: 21 Nov 2024

    Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug. This issue affects: Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507 (MR1)), 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)).

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-48768

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CodeAstrology Team Quantity Plus Minus Button for WooCommerce by CodeAstrology.This issue affects Quantity Plus Minus Button for WooCommerce by CodeAstrology: from n/a through 1.1.9.

    Published: 18 Dec 2023
    4.9
    Medium

    CVE-2023-40691

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 may reveal sensitive information contained in application configuration to developer and administrator users. IBM X-Force ID: 264805.

    Published: 18 Dec 2023
    8.8
    High

    CVE-2023-5882

    Last Modified: 21 Nov 2024

    The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.

    Published: 18 Dec 2023
    7.2
    High

    CVE-2023-4724

    Last Modified: 20 May 2025

    The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

    Published: 18 Dec 2023
    7.5
    High

    CVE-2023-5949

    Last Modified: 21 Nov 2024

    The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.

    Published: 18 Dec 2023
    6.5
    Medium

    CVE-2023-6077

    Last Modified: 21 Nov 2024

    The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected

    Published: 18 Dec 2023
    7.2
    High

    CVE-2023-6295

    Last Modified: 21 Nov 2024

    The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-6289

    Last Modified: 7 May 2025

    The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

    Published: 18 Dec 2023
    6.1
    Medium

    CVE-2023-5348

    Last Modified: 21 Nov 2024

    The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.

    Published: 18 Dec 2023
    8.8
    High

    CVE-2023-4311

    Last Modified: 21 Nov 2024

    The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.

    Published: 18 Dec 2023
    8.8
    High

    CVE-2023-5886

    Last Modified: 21 Nov 2024

    The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

    Published: 18 Dec 2023
    5.3
    Medium

    CVE-2023-6065

    Last Modified: 21 Nov 2024

    The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

    Published: 18 Dec 2023
    9.8
    Critical

    CVE-2023-6272

    Last Modified: 21 Nov 2024

    The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

    Published: 18 Dec 2023
    4.8
    Medium

    CVE-2023-5005

    Last Modified: 7 May 2025

    The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 18 Dec 2023
    7.2
    High

    CVE-2023-6222

    Last Modified: 21 Nov 2024

    IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks

    Published: 18 Dec 2023
    7.5
    High

    CVE-2023-6203

    Last Modified: 21 Nov 2024

    The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request

    Published: 18 Dec 2023
    5.3
    Medium

    CVE-2023-47741

    Last Modified: 21 Nov 2024

    IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532.

    Published: 18 Dec 2023
    7.8
    High

    CVE-2023-6691

    Last Modified: 21 Nov 2024

    Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code execution and gain root privileges.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-48766

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SVGator SVGator – Add Animated SVG Easily.This issue affects SVGator – Add Animated SVG Easily: from n/a through 1.2.4.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-46617

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5.

    Published: 18 Dec 2023
    6.3
    Medium

    CVE-2023-48762

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-48755

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-33214

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-47806

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Saint Systems Disable User Login.This issue affects Disable User Login: from n/a through 1.3.7.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-47789

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a through 2.8.3.

    Published: 18 Dec 2023