Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,306
Critical1,017
High3,377
Medium11,647
Reset
Showing 13641-13660 of 16306 records
Threat Entry Updated 2025-02-04

CVE-2023-2114 - Nex Forms Plugin

The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.

PLUGIN Nex Forms

CVE-2023-2114

HIGH CVSS 7.2 2023-05-08
Threat Entry Updated 2025-05-05

CVE-2023-1806 - Wp Inventory Manager Plugin

The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

PLUGIN Wp Inventory Manager

CVE-2023-1806

MEDIUM CVSS 6.1 2023-05-08
Threat Entry Updated 2025-05-12

CVE-2023-1660 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard

PLUGIN Ai Chatbot

CVE-2023-1660

MEDIUM CVSS 6.1 2023-05-08
Threat Entry Updated 2025-01-29

CVE-2023-1905 - Before 2 Plugin

The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to an insufficient fix of CVE-2023-24003

PLUGIN Before 2

CVE-2023-1905

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-05-12

CVE-2023-1650 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog

PLUGIN Ai Chatbot

CVE-2023-1650

CRITICAL CVSS 9.8 2023-05-08
Threat Entry Updated 2025-01-29

CVE-2023-0768 - Hotels Online Booking Engine Plugin

The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.

PLUGIN Hotels Online Booking Engine

CVE-2023-0768

HIGH CVSS 8.8 2023-05-08
Threat Entry Updated 2025-01-29

CVE-2023-1408 - Video List Manager Plugin

The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

PLUGIN Video List Manager

CVE-2023-1408

HIGH CVSS 7.2 2023-05-08
Threat Entry Updated 2025-02-04

CVE-2023-1347 - Before 0 Plugin

The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

PLUGIN Before 0

CVE-2023-1347

HIGH CVSS 7.2 2023-05-08
Threat Entry Updated 2025-05-12

CVE-2023-1011 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them.

PLUGIN Ai Chatbot

CVE-2023-1011

MEDIUM CVSS 6.1 2023-05-08
Threat Entry Updated 2025-05-12

CVE-2023-1651 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allowing any authenticated users, such as subscriber to update them. Furthermore, due to the lack of escaping of the settings, this could also lead to Stored XSS

PLUGIN Ai Chatbot

CVE-2023-1651

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-05-12

CVE-2023-1649 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Ai Chatbot

CVE-2023-1649

MEDIUM CVSS 4.8 2023-05-08
Threat Entry Updated 2025-01-29

CVE-2023-0894 - Pickup Delivery Dine In Date Time Plugin

The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Pickup Delivery Dine In Date Time

CVE-2023-0894

MEDIUM CVSS 4.8 2023-05-08
Threat Entry Updated 2025-04-23

CVE-2023-0603 - Sloth Logo Customizer Plugin

The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

PLUGIN Sloth Logo Customizer

CVE-2023-0603

HIGH CVSS 8.8 2023-05-08
Threat Entry Updated 2025-02-04

CVE-2023-0514 - Membership Database Plugin

The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Membership Database

CVE-2023-0514

MEDIUM CVSS 6.1 2023-05-08
Threat Entry Updated 2025-05-05

CVE-2023-0421 - Cloud Manager Plugin

The Cloud Manager WordPress plugin through 1.0 does not sanitise and escape the query param ricerca before outputting it in an admin panel, allowing unauthenticated attackers to trick a logged in admin to trigger a XSS payload by clicking a link.

PLUGIN Cloud Manager

CVE-2023-0421

MEDIUM CVSS 6.1 2023-05-08
Threat Entry Updated 2025-02-04

CVE-2023-0542 - Custom Post Type List Shortcode Plugin

The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Custom Post Type List Shortcode

CVE-2023-0542

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-01-29

CVE-2023-0537 - Product Slider For Woocommerce Plugin

The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Product Slider For Woocommerce

CVE-2023-0537

MEDIUM CVSS 5.4 2023-05-08
Threat Entry Updated 2025-05-05

CVE-2023-0536 - Wp D3 Plugin

The Wp-D3 WordPress plugin through 2.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Wp D3

CVE-2023-0536

MEDIUM CVSS 5.4 2023-05-08
Scroll to top