Total
47492 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-28499 | 1 Simonpedge | 1 Slide Anything-responsive Content\/html Slider And Carousel | 2026-06-17 | N/A | 5.4 MEDIUM |
| Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions. | |||||
| CVE-2023-28496 | 1 Smtp2go | 1 Smtp2go | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SMTP2GO – Email Made Easy plugin <= 1.4.2 versions. | |||||
| CVE-2023-28493 | 1 Machothemes | 1 Newsmag | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes NewsMag theme <= 2.4.4 versions. | |||||
| CVE-2023-28490 | 1 Estatik | 1 Estatik Mortgage Calculator | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions. | |||||
| CVE-2023-28485 | 1 Wekan Project | 1 Wekan | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads. | |||||
| CVE-2023-28477 | 1 Concretecms | 1 Concrete Cms | 2026-06-17 | N/A | 5.5 MEDIUM |
| Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter. | |||||
| CVE-2023-28476 | 1 Concretecms | 1 Concrete Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files. | |||||
| CVE-2023-28475 | 1 Concretecms | 1 Concrete Cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized. | |||||
| CVE-2023-28474 | 1 Concretecms | 1 Concrete Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search. | |||||
| CVE-2023-28471 | 1 Concretecms | 1 Concrete Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name. | |||||
| CVE-2023-28467 | 1 Mybb | 1 Mybb | 2026-06-17 | N/A | 6.1 MEDIUM |
| In MyBB before 1.8.34, there is XSS in the User CP module via the user email field. | |||||
| CVE-2023-28447 | 2 Fedoraproject, Smarty | 2 Fedora, Smarty | 2026-06-17 | N/A | 7.1 HIGH |
| Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability. | |||||
| CVE-2023-28439 | 2 Ckeditor, Fedoraproject | 2 Ckeditor, Fedora | 2026-06-17 | N/A | 4.7 MEDIUM |
| CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after fulfilling special conditions: using one of the affected packages on a web page with missing proper Content Security Policy configuration; initializing the editor on an element and using an element other than `<textarea>` as a base; and destroying the editor instance. This vulnerability might affect a small percentage of integrators that depend on dynamic editor initialization/destroy mechanism. A fix is available in CKEditor4 version 4.21.0. In some rare cases, a security fix may be considered a breaking change. Starting from version 4.21.0, the Iframe Dialog plugin applies the `sandbox` attribute by default, which restricts JavaScript code execution in the iframe element. To change this behavior, configure the `config.iframe_attributes` option. Also starting from version 4.21.0, the Media Embed plugin regenerates the entire content of the embed widget by default. To change this behavior, configure the `config.embed_keepOriginalContent` option. Those who choose to enable either of the more permissive options or who cannot upgrade to a patched version should properly configure Content Security Policy to avoid any potential security issues that may arise from embedding iframe elements on their web page. | |||||
| CVE-2023-28435 | 1 Dataease | 1 Dataease | 2026-06-17 | N/A | 6.5 MEDIUM |
| Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been fixed in version 1.18.5. | |||||
| CVE-2023-28429 | 1 Pimcore | 1 Pimcore | 2026-06-17 | N/A | 6.1 MEDIUM |
| Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 10.5.19 or, as a workaround, apply the patch manually. | |||||
| CVE-2023-28423 | 1 Prismtechstudios | 1 Modern Footnotes | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions. | |||||
| CVE-2023-28422 | 1 Mage-people | 1 Event Manager And Tickets Selling For Woocommerce | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions. | |||||
| CVE-2023-28418 | 1 Mediciti Lite Project | 1 Mediciti Lite | 2026-06-17 | N/A | 5.4 MEDIUM |
| Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Yudlee themes Mediciti Lite theme <= 1.3.0 versions. | |||||
| CVE-2023-28415 | 1 Xootix | 1 Side Cart Woocommerce | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XootiX Side Cart Woocommerce (Ajax) plugin <= 2.2 versions. | |||||
| CVE-2023-28414 | 1 Apexchat | 1 Apexchat | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ApexChat plugin <= 1.3.1 versions. | |||||
