Total
403507 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-4800 | 1 Wpdo | 1 Dologin Security | 2026-06-17 | N/A | 6.5 MEDIUM |
| The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users. | |||||
| CVE-2023-4799 | 1 Wpembedfb | 1 Magic Embeds | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |||||
| CVE-2023-4798 | 1 Wpexperts | 1 User Avatar-reloaded | 2026-06-17 | N/A | 5.4 MEDIUM |
| The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks. | |||||
| CVE-2023-4797 | 1 Tribulant | 1 Newsletters | 2026-06-17 | N/A | 7.2 HIGH |
| The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server. | |||||
| CVE-2023-4796 | 1 Booster | 1 Booster For Woocommerce | 2026-06-17 | N/A | 4.3 MEDIUM |
| The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in versions up to, and including, 7.1.0 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabilities or above, to retrieve arbitrary sensitive site options. | |||||
| CVE-2023-4795 | 1 Sazzadh | 1 Testimonial Slider Shortcode | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin | |||||
| CVE-2023-4792 | 1 Inqsys | 1 Duplicate Post Page Menu \& Custom Post Type | 2026-06-17 | N/A | 4.3 MEDIUM |
| The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages. | |||||
| CVE-2023-4785 | 1 Grpc | 1 Grpc | 2026-06-17 | N/A | 7.5 HIGH |
| Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. | |||||
| CVE-2023-4783 | 1 Hoosoft | 1 Magee Shortcodes | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
| CVE-2023-4782 | 1 Hashicorp | 1 Terraform | 2026-06-17 | N/A | 6.3 MEDIUM |
| Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7. | |||||
| CVE-2023-4779 | 1 Plugin-planet | 1 User Submitted Posts | 2026-06-17 | N/A | 6.4 MEDIUM |
| The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due to insufficient input sanitization and output escaping on user supplied attributes like 'before'. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2023-4778 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 5.5 MEDIUM |
| Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV. | |||||
| CVE-2023-4777 | 1 Qualys | 1 Container Scanning Connector | 2026-06-17 | N/A | 3.1 LOW |
| An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins. | |||||
| CVE-2023-4776 | 1 Igexsolutions | 1 Wpschoolpress | 2026-06-17 | N/A | 8.8 HIGH |
| The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers. | |||||
| CVE-2023-4775 | 1 Tinywebgallery | 1 Advanced Iframe | 2026-06-17 | N/A | 6.4 MEDIUM |
| The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2023-51690 appears to be a potential duplicate of this issue. | |||||
| CVE-2023-4774 | 1 Braekling | 1 Connect Matomo | 2026-06-17 | N/A | 6.4 MEDIUM |
| The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik' shortcode in versions up to, and including, 1.0.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2023-4773 | 1 Wordpress Social Login Project | 1 Wordpress Social Login | 2026-06-17 | N/A | 6.4 MEDIUM |
| The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wordpress_social_login_meta' shortcode in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2023-4772 | 1 Thenewsletterplugin | 1 Newsletter | 2026-06-17 | N/A | 6.4 MEDIUM |
| The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2023-4771 | 1 Cksource | 1 Ckeditor | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information. | |||||
| CVE-2023-4770 | 2 4d, Microsoft | 3 4d, Server, Windows | 2026-06-17 | N/A | 6.5 MEDIUM |
| An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution. | |||||
