CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-46789

    Last Modified: 21 Nov 2024

    Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic1' multipart parameter of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-46788

    Last Modified: 21 Nov 2024

    Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter in the 'uploadphoto()' function of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-46787

    Last Modified: 21 Nov 2024

    Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the auth/auth.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46786

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-46785

    Last Modified: 21 Nov 2024

    Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46680

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-46679

    Last Modified: 21 Nov 2024

    Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname_email' parameter of the index.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46678

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-46677

    Last Modified: 21 Nov 2024

    Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46676

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    5.4
    Medium

    CVE-2023-5982

    Last Modified: 8 Apr 2026

    The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update Google Drive remote storage location. This makes it possible for unauthenticated attackers to modify the Google Drive location that backups are sent to via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can make it possible for attackers to receive backups for a site which may contain sensitive information.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-5999

    Last Modified: 13 Nov 2023

    This is a duplicate.

    Published: 7 Nov 2023
    4.4
    Medium

    CVE-2023-5819

    Last Modified: 8 Apr 2026

    The Amazonify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. However, please note that this can also be combined with CVE-2023-5818 for CSRF to XSS.

    Published: 7 Nov 2023
    4.3
    Medium

    CVE-2023-5818

    Last Modified: 8 Apr 2026

    The Amazonify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8.1. This is due to missing or incorrect nonce validation on the amazonifyOptionsPage() function. This makes it possible for unauthenticated attackers to update the plugins settings, including the Amazon Tracking ID, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 7 Nov 2023
    9.9
    Critical

    CVE-2023-46243

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user have edit right on it. A crafted URL of the form ` /xwiki/bin/edit//?content=%7B%7Bgroovy%7D%7Dprintln%28%22Hello+from+Groovy%21%22%29%7B%7B%2Fgroovy%7D%7D&xpage=view` can be used to execute arbitrary groovy code on the server. This vulnerability has been patched in XWiki versions 14.10.6 and 15.2RC1. Users are advised to update. There are no known workarounds for this issue.

    Published: 7 Nov 2023
    9.6
    Critical

    CVE-2023-46242

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges in order to exploit this vulnerability. This issue has been patched in XWiki 14.10.7 and 15.2RC1. Users are advised to upgrade. There are no known workarounds for for this vulnerability.

    Published: 7 Nov 2023
    9.1
    Critical

    CVE-2023-46244

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to write a script in which any velocity content is executed with the right of any other document content author. Since this API require programming right and the user does not have it, the expected result is `$doc.document.authors.contentAuthor` (not executed script), unfortunately with the security vulnerability it is possible for the attacker to get `XWiki.superadmin` which shows that the title was executed with the right of the unmodified document. This has been patched in XWiki versions 14.10.7 and 15.2RC1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Nov 2023
    6.8
    Medium

    CVE-2023-5309

    Last Modified: 21 Nov 2024

    Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

    Published: 7 Nov 2023
    6.8
    Medium

    CVE-2023-46252

    Last Modified: 21 Nov 2024

    Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The editor-sdk.js file defines three different class-like functions, which employ a global message event listener: SquidexSidebar, SquidexWidget, and SquidexFormField. The registered event listener takes some action based on the type of the received message. For example, when the SquidexFormField receives a message with the type valueChanged, the value property is updated. The SquidexFormField class is for example used in the editor-editorjs.html file, which can be accessed via the public wwwroot folder. It uses the onValueChanged method to register a callback function, which passes the value provided from the message event to the editor.render. Passing an attacker-controlled value to this function introduces a Cross-Site Scripting (XSS) vulnerability.

    Published: 7 Nov 2023
    9.1
    Critical

    CVE-2023-46253

    Last Modified: 21 Nov 2024

    Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain remote code execution (RCE). Squidex allows users with the `squidex.admin.restore` permission to create and restore backups. Part of these backups are the assets uploaded to an App. For each asset, the backup zip archive contains a `.asset` file with the actual content of the asset as well as a related `AssetCreatedEventV2` event, which is stored in a JSON file. Amongst other things, the JSON file contains the event type (`AssetCreatedEventV2`), the ID of the asset (`46c05041-9588-4179-b5eb-ddfcd9463e1e`), its filename (`test.txt`), and its file version (`0`). When a backup with this event is restored, the `BackupAssets.ReadAssetAsync` method is responsible for re-creating the asset. For this purpose, it determines the name of the `.asset` file in the zip archive, reads its content, and stores the content in the filestore. When the asset is stored in the filestore via the UploadAsync method, the assetId and fileVersion are passed as arguments. These are further passed to the method GetFileName, which determines the filename where the asset should be stored. The assetId is inserted into the filename without any sanitization and an attacker with squidex.admin.restore privileges to run arbitrary operating system commands on the underlying server (RCE).

    Published: 7 Nov 2023
    7.5
    High

    CVE-2023-5998

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.

    Published: 7 Nov 2023
    7.4
    High

    CVE-2023-46730

    Last Modified: 21 Nov 2024

    Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api/upload.php endpoint. The /api/upload.php endpoint does not filter URLs which allows a malicious user to cause the server to make resource requests to untrusted domains. Note that protocols like file:// can also be used to access the server disk. The request result (on success) can then be retrieved using /api/download.php. This issue has been addressed in versions 6.8.15, 6.7.54, and 6.6.177. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Nov 2023
    5.4
    Medium

    CVE-2023-28499

    Last Modified: 21 Nov 2024

    Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions.

    Published: 7 Nov 2023
    5.4
    Medium

    CVE-2023-32966

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popups: from n/a through 1.8.7.

    Published: 7 Nov 2023
    4.3
    Medium

    CVE-2022-47181

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpexpertsio Email Templates Customizer and Designer for WordPress and WooCommerce email-templates allows Cross Site Request Forgery.This issue affects Email Templates Customizer and Designer for WordPress and WooCommerce: from n/a through 1.4.2.

    Published: 7 Nov 2023
    5.4
    Medium

    CVE-2023-46744

    Last Modified: 21 Nov 2024

    Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering mechanism intended to stop XSS attacks through uploaded SVG images, is insufficient resulting to stored XSS attacks. Squidex allows the CMS contributors to be granted the permission of uploading an SVG asset. When the asset is uploaded, a filtering mechanism is performed to validate that the SVG does not contain malicious code. The validation logic consists of traversing the HTML nodes in the DOM. In order for the validation to succeed, 2 conditions must be met: 1. No HTML tags included in a "blacklist" called "InvalidSvgElements" are present. This list only contains the element "script". and 2. No attributes of HTML tags begin with "on" (i.e. onerror, onclick) (line 65). If either of the 2 conditions is not satisfied, validation fails and the file/asset is not uploaded. However it is possible to bypass the above filtering mechanism and execute arbitrary JavaScript code by introducing other HTML elements such as an <iframe> element with a "src" attribute containing a "javascript:" value. Authenticated adversaries with the "assets.create" permission, can leverage this vulnerability to upload a malicious SVG as an asset, targeting any registered user that will attempt to open/view the asset through the Squidex CMS.

    Published: 7 Nov 2023
    5.1
    Medium

    CVE-2023-41798

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1.

    Published: 7 Nov 2023
    7.6
    High

    CVE-2022-41616

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1.

    Published: 7 Nov 2023
    5.8
    Medium

    CVE-2022-38702

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Nakashima Masahiro WP CSV Exporter.This issue affects WP CSV Exporter: from n/a through 2.0.

    Published: 7 Nov 2023
    5.8
    Medium

    CVE-2022-42882

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Shambix Simple CSV/XLS Exporter.This issue affects Simple CSV/XLS Exporter: from n/a through 1.5.8.

    Published: 7 Nov 2023
    5.8
    Medium

    CVE-2022-44738

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Patrick Robrecht Posts and Users Stats.This issue affects Posts and Users Stats: from n/a through 1.1.3.

    Published: 7 Nov 2023
    5.9
    Medium

    CVE-2022-45078

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5.

    Published: 7 Nov 2023
    4.7
    Medium

    CVE-2022-45360

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Scott Reilly Commenter Emails.This issue affects Commenter Emails: from n/a through 2.6.1.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-47638

    Last Modified: 15 Nov 2023

    Confirm reference is not public.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2022-45370

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1.

    Published: 7 Nov 2023
    5.8
    Medium

    CVE-2022-45348

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in anmari amr users.This issue affects amr users: from n/a through 4.59.4.

    Published: 7 Nov 2023
    4.7
    Medium

    CVE-2022-45810

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This issue affects Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce: from n/a through 5.5.2.

    Published: 7 Nov 2023
    5.8
    Medium

    CVE-2022-46821

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Jackmail & Sarbacane Emails & Newsletters with Jackmail.This issue affects Emails & Newsletters with Jackmail: from n/a through 1.2.22.

    Published: 7 Nov 2023
    5.8
    Medium

    CVE-2022-46804

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2022-46803

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Noptin Newsletter Simple Newsletter Plugin – Noptin.This issue affects Simple Newsletter Plugin – Noptin: from n/a through 1.9.5.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2022-46809

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.

    Published: 7 Nov 2023
    5.3
    Medium

    CVE-2023-0898

    Last Modified: 16 Jan 2025

    General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the application.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2022-46801

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Paul Ryley Site Reviews.This issue affects Site Reviews: from n/a through 6.2.0.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2022-46802

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export for WooCommerce: from n/a through 1.4.8.

    Published: 7 Nov 2023
    4.7
    Medium

    CVE-2023-36527

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebSoft.This issue affects Post to CSV by BestWebSoft: from n/a through 1.4.0.

    Published: 7 Nov 2023
    4.7
    Medium

    CVE-2023-23796

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Muneeb Form Builder | Create Responsive Contact Forms.This issue affects Form Builder | Create Responsive Contact Forms: from n/a through 1.9.9.0.

    Published: 7 Nov 2023
    4
    Medium

    CVE-2023-23678

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in WPEkaClub WP Cookie Consent ( for GDPR, CCPA & ePrivacy ).This issue affects WP Cookie Consent ( for GDPR, CCPA & ePrivacy ): from n/a through 2.2.5.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2022-45357

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Lenderd 1003 Mortgage Application.This issue affects 1003 Mortgage Application: from n/a through 1.75.

    Published: 7 Nov 2023
    7.8
    High

    CVE-2023-4295

    Last Modified: 16 Dec 2025

    A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

    Published: 7 Nov 2023
    4.7
    Medium

    CVE-2023-22719

    Last Modified: 28 Apr 2026

    Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1.

    Published: 7 Nov 2023