Total
47486 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-46074 | 1 Borbis | 1 Freshmail For Wordpress | 2026-06-17 | N/A | 5.8 MEDIUM |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Borbis Media FreshMail For WordPress plugin <= 2.3.2 versions. | |||||
| CVE-2023-46072 | 1 Add Shortcodes Actions And Filters Project | 1 Add Shortcodes Actions And Filters | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions. | |||||
| CVE-2023-46071 | 1 Clickdatos | 1 Proteccion De Datos Rgpd | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickDatos Protección de Datos RGPD plugin <= 3.1.0 versions. | |||||
| CVE-2023-46070 | 1 Egeorjon | 1 Eg-attachments | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Emmanuel GEORJON EG-Attachments plugin <= 2.1.3 versions. | |||||
| CVE-2023-46069 | 1 Osmansorkar | 1 Ajax Archive Calendar | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.7 versions. | |||||
| CVE-2023-46068 | 1 Maileon | 1 Maileon | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XQueue GmbH Maileon for WordPress plugin <= 2.16.0 versions. | |||||
| CVE-2023-46066 | 1 Codedraft | 1 Mediabay - Wordpress Media Library Folders | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Codedrafty Mediabay – Media Library Folders plugin <= 1.6 versions. | |||||
| CVE-2023-46059 | 1 Geeklog | 1 Geeklog | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the Service, and website URL to Ping parameters of the admin/trackback.php component. | |||||
| CVE-2023-46058 | 1 Geeklog | 1 Geeklog | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the grp_desc parameter of the admin/group.php component. | |||||
| CVE-2023-46054 | 1 Wbce | 1 Wbce Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component. | |||||
| CVE-2023-46040 | 1 Get-simple | 1 Getsimplecms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function. | |||||
| CVE-2023-46026 | 1 Phpgurukul | 1 Teacher Subject Allocation Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary code via the 'adminname' and 'email' parameters. | |||||
| CVE-2023-46020 | 1 Code-projects | 1 Blood Bank | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters. | |||||
| CVE-2023-46019 | 1 Code-projects | 1 Blood Bank | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter. | |||||
| CVE-2023-46016 | 1 Code-projects | 1 Blood Bank | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL. | |||||
| CVE-2023-46015 | 1 Code-projects | 1 Blood Bank | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL. | |||||
| CVE-2023-46003 | 1 I-doit | 1 I-doit | 2026-06-17 | N/A | 5.4 MEDIUM |
| I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php. | |||||
| CVE-2023-45998 | 1 Kodcloud | 1 Kodbox | 2026-06-17 | N/A | 5.4 MEDIUM |
| kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS. | |||||
| CVE-2023-45958 | 1 Thirtybees | 1 Thirty Bees | 2026-06-17 | N/A | 6.1 MEDIUM |
| Thirty Bees Core v1.4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the backup_pagination parameter at /controller/AdminController.php. This vulnerability allows attackers to execute arbitrary JavaScript in the web browser of a user via a crafted payload. | |||||
| CVE-2023-45957 | 1 Thirtybees | 1 Thirty Bees | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the component admin/AdminRequestSqlController.php of thirty bees before 1.5.0 allows attackers to execute arbitrary web script or HTML via $e->getMessage() error mishandling. | |||||
