CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2023-6435

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory/batches_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6434

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory/sections_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6433

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory/suppliers_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6432

    Last Modified: 22 May 2025

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory/items_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6431

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory/categories_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6430

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory/transactions_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-34030

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6.4.7.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6429

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicing/app/clients_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6428

    Last Modified: 3 Jun 2025

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicing/app/items_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6427

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicing/app/invoices_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6426

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicing/app/invoices_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6425

    Last Modified: 6 Feb 2026

    A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/medical_records_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6424

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/disease_symptoms_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6423

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/events_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    6.3
    Medium

    CVE-2023-6422

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/patients_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

    Published: 30 Nov 2023
    7.1
    High

    CVE-2023-36682

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-36685

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlows Pro: from n/a through 1.11.12.

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-49787

    Last Modified: 7 Dec 2023

    CVE request originates from private repository

    Published: 30 Nov 2023
    6.1
    Medium

    CVE-2023-6027

    Last Modified: 21 Nov 2024

    A critical flaw has been identified in elijaa/phpmemcachedadmin affecting version 1.3.0, specifically related to a stored XSS vulnerability. This vulnerability allows malicious actors to insert a carefully crafted JavaScript payload. The issue arises from improper encoding of user-controlled entries in the "/pmcadmin/configure.php" parameter.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6026

    Last Modified: 21 Nov 2024

    A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete files stored on the server due to lack of proper verification of user-supplied input.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-47645

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Cross Site Request Forgery.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.2.6.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-4770

    Last Modified: 21 Nov 2024

    An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-47827

    Last Modified: 28 Apr 2026

    Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Events Addon for Elementor: from n/a through 2.1.3.

    Published: 30 Nov 2023
    4.7
    Medium

    CVE-2023-5966

    Last Modified: 20 Apr 2026

    An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.

    Published: 30 Nov 2023
    4.7
    Medium

    CVE-2023-5965

    Last Modified: 20 Apr 2026

    An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-6420

    Last Modified: 3 Jun 2025

    A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via signup2.php in the emailadd parameter, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-6419

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via editprofile.php in multiple parameters, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6418

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via videos.php in the id parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-48279

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source allows Cross Site Request Forgery.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.6.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6417

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via update.php in the id parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6416

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signup2.php in the emailadd parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6415

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signin.php in the user parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6414

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via perfil.php in the id and user parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6413

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photos.php in the id and user parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6412

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photo.php in multiple parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6411

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via home.php in the update parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-6410

    Last Modified: 21 Nov 2024

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via editprofile.php in multiple parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-48281

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Super Blog Me Broken Link Checker for YouTube allows Cross Site Request Forgery.This issue affects Broken Link Checker for YouTube: from n/a through 1.3.

    Published: 30 Nov 2023
    5.4
    Medium

    CVE-2023-48282

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio Taxonomy filter allows Cross Site Request Forgery.This issue affects Taxonomy filter: from n/a through 2.2.9.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-48283

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Testimonials Showcase allows Cross Site Request Forgery.This issue affects Simple Testimonials Showcase: from n/a through 1.1.5.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-48284

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue affects Decorator – WooCommerce Email Customizer: from n/a through 1.2.7.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-48323

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

    Published: 30 Nov 2023
    5.4
    Medium

    CVE-2023-48330

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Mike Strand Bulk Comment Remove allows Cross Site Request Forgery.This issue affects Bulk Comment Remove: from n/a through 2.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-48331

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore by Stormhill Media allows Cross Site Request Forgery.This issue affects MyBookTable Bookstore by Stormhill Media: from n/a through 3.3.4.

    Published: 30 Nov 2023
    5.4
    Medium

    CVE-2023-48334

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in DAEXT League Table allows Cross Site Request Forgery.This issue affects League Table: from n/a through 1.13.

    Published: 30 Nov 2023
    5.4
    Medium

    CVE-2023-6137

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in finnj Frontier Post allows Cross Site Request Forgery.This issue affects Frontier Post: from n/a through 6.1.

    Published: 30 Nov 2023
    8.4
    High

    CVE-2023-6071

    Last Modified: 21 Nov 2024

    An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source.

    Published: 30 Nov 2023
    5.4
    Medium

    CVE-2023-48744

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Offshore Web Master Availability Calendar allows Cross Site Request Forgery.This issue affects Availability Calendar: from n/a through 1.2.6.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-32291

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MonsterInsights Pro allows Stored XSS.This issue affects MonsterInsights Pro: from n/a through 8.14.1.

    Published: 30 Nov 2023
    7.1
    High

    CVE-2023-38474

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Reflected XSS.This issue affects Campaign Monitor for WordPress: from n/a through 2.8.12.

    Published: 30 Nov 2023