Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13621-13640 of 16306 records
Threat Entry Updated 2025-01-24

CVE-2023-1890 - Before 1 Plugin

The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2023-1890

MEDIUM CVSS 6.1 2023-05-15
Threat Entry Updated 2025-01-14

CVE-2023-1835 - Ninja Forms Contact Form Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Ninja Forms Contact Form

CVE-2023-1835

MEDIUM CVSS 6.1 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-1596 - Tagdiv Composer Plugin

The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Tagdiv Composer

CVE-2023-1596

MEDIUM CVSS 6.1 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-1019 - Help Desk Wp Plugin

The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.

PLUGIN Help Desk Wp

CVE-2023-1019

MEDIUM CVSS 5.4 2023-05-15
Threat Entry Updated 2025-01-14

CVE-2023-2009 - Pretty Url Plugin

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Pretty Url

CVE-2023-2009

MEDIUM CVSS 4.8 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-1839 - Fields For Woocommerce Plugin

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

PLUGIN Fields For Woocommerce

CVE-2023-1839

MEDIUM CVSS 4.8 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-0892 - Bizlibrary Plugin

The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Bizlibrary

CVE-2023-0892

MEDIUM CVSS 4.8 2023-05-15
Threat Entry Updated 2026-03-06

CVE-2023-0600 - Before 6 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

PLUGIN Before 6

CVE-2023-0600

CRITICAL CVSS 9.8 2023-05-15
Threat Entry Updated 2025-01-14

CVE-2023-0644 - Push Notifications Plugin

The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Push Notifications

CVE-2023-0644

MEDIUM CVSS 6.1 2023-05-15
Threat Entry Updated 2025-01-24

CVE-2023-0520 - Rapidexpcart Plugin

The RapidExpCart WordPress plugin through 1.0 does not sanitize and escape the url parameter in the rapidexpcart endpoint before storing it and outputting it back in the page, leading to a Stored Cross-Site Scripting vulnerability which could be used against high-privilege users such as admin, furthermore lack of csrf protection means an attacker can trick a logged in admin to perform the attack by submitting a hidden form.

PLUGIN Rapidexpcart

CVE-2023-0520

MEDIUM CVSS 5.4 2023-05-15
Threat Entry Updated 2025-01-14

CVE-2023-0490 - F X Toc Plugin

The f(x) TOC WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN F X Toc

CVE-2023-0490

MEDIUM CVSS 5.4 2023-05-15
Threat Entry Updated 2025-01-14

CVE-2023-0233 - Before 8 Plugin

The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 8

CVE-2023-0233

MEDIUM CVSS 5.4 2023-05-15
Threat Entry Updated 2025-01-27

CVE-2023-27918 - Ameliabooking Plugin

Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious URL.

PLUGIN Ameliabooking

CVE-2023-27918

MEDIUM CVSS 6.1 2023-05-10
Threat Entry Updated 2024-11-21

CVE-2023-1979 - Web Stories for WordPress Plugin

The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't have the ability to edit password protected stories. The vulnerability allowed users with said role to bypass this permission check when trying to duplicate the protected story in the plugin's own dashboard, giving them access to the seemingly protected content. We recommend upgrading to version 1.32 or beyond…

PLUGIN Web Stories for WordPress

CVE-2023-1979

MEDIUM CVSS 4.9 2023-05-08
Scroll to top