CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-4823

    Last Modified: 23 Apr 2025

    The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-5458

    Last Modified: 21 Nov 2024

    The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-5360

    Last Modified: 13 Feb 2025

    The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

    Published: 31 Oct 2023
    4.8
    Medium

    CVE-2023-5229

    Last Modified: 23 Apr 2025

    The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 31 Oct 2023
    8.2
    High

    CVE-2023-24000

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through 2.5.7.

    Published: 31 Oct 2023
    5.5
    Medium

    CVE-2023-25047

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.

    Published: 31 Oct 2023
    6.7
    Medium

    CVE-2023-25045

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.

    Published: 31 Oct 2023
    6.4
    Medium

    CVE-2023-5116

    Last Modified: 8 Apr 2026

    The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpull_page' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Oct 2023
    8.1
    High

    CVE-2016-1203

    Last Modified: 21 Nov 2024

    Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may result in a malicious file being downloaded and executed.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5099

    Last Modified: 8 Apr 2026

    The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-5114

    Last Modified: 8 Apr 2026

    The idbbee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idbbee' shortcode in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Oct 2023
    6.4
    Medium

    CVE-2023-5073

    Last Modified: 8 Apr 2026

    The iframe forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'iframe' shortcode in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Oct 2023
    8.1
    High

    CVE-2022-3007

    Last Modified: 21 Nov 2024

    The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Device Firmware Update (DFU) which is used for performing Over-The-Air (OTA) firmware updates on the Bluetooth Low Energy (BLE) devices. An unauthenticated attacker could exploit this vulnerability by setting arbitrary values to handle on the vulnerable device over Bluetooth. Successful exploitation of this vulnerability could allow the attacker to perform firmware update, device reboot or data manipulation on the target device.

    Published: 31 Oct 2023
    5.9
    Medium

    CVE-2023-40681

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11.10 versions.

    Published: 31 Oct 2023
    7.1
    High

    CVE-2023-46622

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.18.2 versions.

    Published: 31 Oct 2023
    7.1
    High

    CVE-2023-46313

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.4 versions.

    Published: 31 Oct 2023
    5.9
    Medium

    CVE-2015-2968

    Last Modified: 21 Nov 2024

    LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.

    Published: 31 Oct 2023
    5.9
    Medium

    CVE-2015-0897

    Last Modified: 21 Nov 2024

    LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.

    Published: 31 Oct 2023
    7.1
    High

    CVE-2023-46312

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 versions.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5433

    Last Modified: 8 Apr 2026

    The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5436

    Last Modified: 8 Apr 2026

    The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5437

    Last Modified: 8 Apr 2026

    The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5438

    Last Modified: 8 Apr 2026

    The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5431

    Last Modified: 8 Apr 2026

    The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5429

    Last Modified: 8 Apr 2026

    The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5439

    Last Modified: 8 Apr 2026

    The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5430

    Last Modified: 8 Apr 2026

    The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5434

    Last Modified: 8 Apr 2026

    The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5435

    Last Modified: 8 Apr 2026

    The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5412

    Last Modified: 8 Apr 2026

    The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5464

    Last Modified: 8 Apr 2026

    The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5428

    Last Modified: 8 Apr 2026

    The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-5873

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.

    Published: 31 Oct 2023
    5.9
    Medium

    CVE-2023-46210

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebCource WC Captcha plugin <= 1.4 versions.

    Published: 31 Oct 2023
    5.7
    Medium

    CVE-2023-5866

    Last Modified: 21 Nov 2024

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-5867

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-5865

    Last Modified: 21 Nov 2024

    Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

    Published: 31 Oct 2023
    4.8
    Medium

    CVE-2023-5864

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

    Published: 31 Oct 2023
    6.1
    Medium

    CVE-2023-5863

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

    Published: 31 Oct 2023
    4.8
    Medium

    CVE-2023-5861

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

    Published: 31 Oct 2023
    3.3
    Low

    CVE-2023-5862

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository hamza417/inure prior to Build95.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-36263

    Last Modified: 12 Jun 2026

    Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46977

    Last Modified: 21 Nov 2024

    TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46979

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.

    Published: 31 Oct 2023
    6.1
    Medium

    CVE-2019-25155

    Last Modified: 21 Nov 2024

    DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46484

    Last Modified: 21 Nov 2024

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46485

    Last Modified: 21 Nov 2024

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2023-46992

    Last Modified: 21 Nov 2024

    TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2015-20110

    Last Modified: 21 Nov 2024

    JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2023-45955

    Last Modified: 21 Nov 2024

    An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands.

    Published: 31 Oct 2023