Security Vulnerabilities, CVEs
CVE-2023-50871
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
Max CVSS
4.3
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-50870
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
Max CVSS
8.8
Published
2023-12-15
Updated
2023-12-19
EPSS
0.06%
CVE-2023-50860
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TMS Booking for Appointments and Events Calendar – Amelia allows Stored XSS.This issue affects Booking for Appointments and Events Calendar – Amelia: from n/a through 1.0.85.
Max CVSS
6.5
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50859
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through 2.1.6.
Max CVSS
6.5
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50858
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan.This issue affects Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan: from n/a through 4.34.
Max CVSS
5.4
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50857
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit.This issue affects Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit: from n/a through 2.6.1.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50856
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits.This issue affects Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits: from n/a through 2.14.3.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50855
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sam Perrow Pre* Party Resource Hints.This issue affects Pre* Party Resource Hints: from n/a through 1.8.18.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50854
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly Squirrly SEO - Advanced Pack.This issue affects Squirrly SEO - Advanced Pack: from n/a through 2.3.8.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50853
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nasirahmed Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms.This issue affects Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms: from n/a through 1.75.0.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50852
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Booking Calendar | Appointment Booking | BookIt.This issue affects Booking Calendar | Appointment Booking | BookIt: from n/a through 2.4.3.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50851
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N Squared Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin.This issue affects Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin: from n/a before 1.6.6.1.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50849
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.23.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50848
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.34.0.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50847
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Collne Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.3.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50846
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.5.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50845
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: from n/a through 2.3.28.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50844
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in James Ward Mail logging – WP Mail Catcher.This issue affects Mail logging – WP Mail Catcher: from n/a through 2.1.3.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50843
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Clockwork Clockwork SMS Notfications.This issue affects Clockwork SMS Notfications: from n/a through 3.0.4.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50842
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1.
Max CVSS
8.5
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50841
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin.This issue affects BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin: from n/a through 1.0.72.
Max CVSS
8.5
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50840
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop, oplugins Booking Manager.This issue affects Booking Manager: from n/a through 2.1.5.
Max CVSS
8.5
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50839
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1.
Max CVSS
9.3
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50838
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder – Contact forms and much more: from n/a through 8.5.5.
Max CVSS
7.6
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-50837
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lockdown – Protect Login Form: from n/a through 2.06.
Max CVSS
7.6
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%