Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2023-0320

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Izmir Katip Celebi University UBYS allows Stored XSS.This issue affects UBYS: before 23.03.16. ... Read more

    • Published: Mar. 20, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0402

    The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level perm... Read more

    Affected Products : social_warfare
    • Published: Jan. 19, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0165

    The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform ... Read more

    Affected Products : cost_calculator
    • Published: Mar. 06, 2023
    • Modified: Mar. 06, 2025
  • 5.4

    MEDIUM
    CVE-2023-0166

    The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contr... Read more

    Affected Products : product_slider_for_woocommerce
    • Published: Feb. 13, 2023
    • Modified: Mar. 21, 2025
  • 5.4

    MEDIUM
    CVE-2023-0146

    The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stor... Read more

    Affected Products : naver_map
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2017-1000023

    LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.... Read more

    Affected Products : logicaldoc
    • Published: Jul. 17, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2023-0173

    The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role... Read more

    Affected Products : drag_\&_drop_sales_funnel_builder
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0154

    The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more

    Affected Products : gamipress gamipress_-_reset_user
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0143

    The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site S... Read more

    Affected Products : send_pdf_for_contact_form_7
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0404

    The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, wi... Read more

    Affected Products : events_made_easy
    • Published: Jan. 19, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0177

    The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor rol... Read more

    Affected Products : social_like_box_and_page
    • Published: Feb. 13, 2023
    • Modified: Mar. 20, 2025
  • 5.4

    MEDIUM
    CVE-2023-0066

    The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and a... Read more

    Affected Products : companion_sitemap_generator
    • Published: Mar. 13, 2023
    • Modified: Feb. 27, 2025
  • 5.4

    MEDIUM
    CVE-2023-0072

    The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more

    Affected Products : wc_vendors_marketplace
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0082

    The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross... Read more

    Affected Products : exactmetrics
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0148

    The Gallery Factory Lite WordPress plugin through 2.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more

    Affected Products : gallery_factory_lite
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0155

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown... Read more

    Affected Products : gitlab
    • Published: May. 03, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0094

    The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to per... Read more

    Affected Products : upqode_google_maps
    • Published: Jan. 16, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0144

    The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perfor... Read more

    • Published: Feb. 06, 2023
    • Modified: Mar. 26, 2025
  • 5.4

    MEDIUM
    CVE-2023-0149

    The WordPrezi WordPress plugin before 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored ... Read more

    Affected Products : wordprezi
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0015

    In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intel... Read more

    • Published: Jan. 10, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 293664 Results