CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2023-4888

    Last Modified: 8 Apr 2026

    The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sfp-page-plugin' shortcode in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5660

    Last Modified: 8 Apr 2026

    The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5567

    Last Modified: 8 Apr 2026

    The QR Code Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'qrcodetag' shortcode in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-4842

    Last Modified: 8 Apr 2026

    The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5661

    Last Modified: 8 Apr 2026

    The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcode in all versions up to, and including, 1.5.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    8.8
    High

    CVE-2023-5709

    Last Modified: 8 Apr 2026

    The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5659

    Last Modified: 8 Apr 2026

    The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'interact-quiz' shortcode in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5703

    Last Modified: 8 Apr 2026

    The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'giftup' shortcode in all versions up to, and including, 2.20.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5577

    Last Modified: 8 Apr 2026

    The Bitly's plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpbitly' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5669

    Last Modified: 8 Apr 2026

    The Featured Image Caption plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and post meta in all versions up to, and including, 0.8.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    5.3
    Medium

    CVE-2023-46819

    Last Modified: 21 Nov 2024

    Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09.  Users are recommended to upgrade to version 18.12.09

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2023-5532

    Last Modified: 8 Apr 2026

    The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. This is due to missing or incorrect nonce validation on the 'imgmap_save_area_title' function. This makes it possible for unauthenticated attackers to update the post title and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5507

    Last Modified: 8 Apr 2026

    The ImageMapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'imagemap' shortcode in versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    4.3
    Medium

    CVE-2023-5975

    Last Modified: 8 Apr 2026

    The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to update the plugin settings via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5658

    Last Modified: 8 Apr 2026

    The WP MapIt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_mapit' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    5.4
    Medium

    CVE-2023-5506

    Last Modified: 8 Apr 2026

    The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'imgmap_delete_area_ajax' function in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts and pages.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5743

    Last Modified: 8 Apr 2026

    The Telephone Number Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'telnumlink' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    3.5
    Low

    CVE-2021-4431

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of the file FMDataAPI_Sample.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 23 is able to address this issue. The patch is identified as 3bd1709a8f7b1720529bf5dfc9855ad609f436cf. It is recommended to upgrade the affected component. VDB-244494 is the identifier assigned to this vulnerability.

    Published: 7 Nov 2023
    7.1
    High

    CVE-2023-47510

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPSolutions-HQ WPDBSpringClean plugin <= 1.6 versions.

    Published: 7 Nov 2023
    4.9
    Medium

    CVE-2023-46851

    Last Modified: 21 Nov 2024

    Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them.  Exposing internal files then can lead to other exploits, like session hijacking, or remote code execution. This issue affects Apache Allura from 1.0.1 through 1.15.0. Users are recommended to upgrade to version 1.16.0, which fixes the issue.  If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file.

    Published: 7 Nov 2023
    6.3
    Medium

    CVE-2023-42555

    Last Modified: 21 Nov 2024

    Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetooth address of user device.

    Published: 7 Nov 2023
    5.4
    Medium

    CVE-2023-42554

    Last Modified: 6 Mar 2025

    Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.

    Published: 7 Nov 2023
    4
    Medium

    CVE-2023-42553

    Last Modified: 6 Mar 2025

    Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.

    Published: 7 Nov 2023
    4.4
    Medium

    CVE-2023-42552

    Last Modified: 21 Nov 2024

    Implicit intent hijacking vulnerability in Firewall application prior to versions 12.1.00.24 in Android 11, 13.1.00.16 in Android 12 and 14.1.00.7 in Android 13 allows 3rd party application to tamper the database of Firewall.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-42551

    Last Modified: 21 Nov 2024

    Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-42550

    Last Modified: 21 Nov 2024

    Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-42549

    Last Modified: 21 Nov 2024

    Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-42548

    Last Modified: 11 Jun 2025

    Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-42547

    Last Modified: 21 Nov 2024

    Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-42546

    Last Modified: 21 Nov 2024

    Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-42545

    Last Modified: 21 Nov 2024

    Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-42544

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

    Published: 7 Nov 2023
    6.2
    Medium

    CVE-2023-42543

    Last Modified: 21 Nov 2024

    Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.

    Published: 7 Nov 2023
    3.3
    Low

    CVE-2023-42542

    Last Modified: 6 Mar 2025

    Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device.

    Published: 7 Nov 2023
    4
    Medium

    CVE-2023-42541

    Last Modified: 6 Mar 2025

    Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

    Published: 7 Nov 2023
    4
    Medium

    CVE-2023-42540

    Last Modified: 6 Mar 2025

    Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.

    Published: 7 Nov 2023
    4.7
    Medium

    CVE-2023-42539

    Last Modified: 21 Nov 2024

    PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.

    Published: 7 Nov 2023
    5.9
    Medium

    CVE-2023-42538

    Last Modified: 21 Nov 2024

    An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

    Published: 7 Nov 2023
    8.4
    High

    CVE-2023-42537

    Last Modified: 21 Nov 2024

    An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

    Published: 7 Nov 2023
    8.4
    High

    CVE-2023-42536

    Last Modified: 11 Jun 2025

    An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

    Published: 7 Nov 2023
    8.4
    High

    CVE-2023-42535

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 7 Nov 2023
    6.3
    Medium

    CVE-2023-42534

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.

    Published: 7 Nov 2023
    6.6
    Medium

    CVE-2023-42533

    Last Modified: 21 Nov 2024

    Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.

    Published: 7 Nov 2023
    5.9
    Medium

    CVE-2023-42532

    Last Modified: 21 Nov 2024

    Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.

    Published: 7 Nov 2023
    6.2
    Medium

    CVE-2023-42531

    Last Modified: 12 Jun 2025

    Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.

    Published: 7 Nov 2023
    6.7
    Medium

    CVE-2023-42530

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction.

    Published: 7 Nov 2023
    6.7
    Medium

    CVE-2023-42529

    Last Modified: 21 Nov 2024

    Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.

    Published: 7 Nov 2023
    6.7
    Medium

    CVE-2023-42528

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 7 Nov 2023
    5.6
    Medium

    CVE-2023-42527

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.

    Published: 7 Nov 2023
    6.7
    Medium

    CVE-2023-30739

    Last Modified: 21 Nov 2024

    Arbitrary File Descriptor Write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 7 Nov 2023