CVE-2023-49874

Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
Max CVSS
4.3
Published
2023-12-12
Updated
2023-12-14
EPSS
0.05%

CVE-2023-49860

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts allows Stored XSS.This issue affects WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts: from n/a through 2.6.7.
Max CVSS
6.5
Published
2023-12-14
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49855

Cross-Site Request Forgery (CSRF) vulnerability in BinaryCarpenter Menu Bar Cart Icon For WooCommerce By Binary Carpenter.This issue affects Menu Bar Cart Icon For WooCommerce By Binary Carpenter: from n/a through 1.49.3.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%

CVE-2023-49854

Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue affects Caddy – Smart Side Cart for WooCommerce: from n/a through 1.9.7.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%

CVE-2023-49853

Cross-Site Request Forgery (CSRF) vulnerability in PayTR Ödeme ve Elektronik Para Kurulu?u A.?. PayTR Taksit Tablosu – WooCommerce.This issue affects PayTR Taksit Tablosu – WooCommerce: from n/a through 1.3.1.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%

CVE-2023-49847

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0.
Max CVSS
6.5
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%

CVE-2023-49846

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.17.
Max CVSS
6.5
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%

CVE-2023-49844

Cross-Site Request Forgery (CSRF) vulnerability in Kevin Ohashi WPPerformanceTester.This issue affects WPPerformanceTester: from n/a through 2.0.0.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%

CVE-2023-49843

Cross-Site Request Forgery (CSRF) vulnerability in QuanticEdge First Order Discount Woocommerce.This issue affects First Order Discount Woocommerce: from n/a through 1.21.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%

CVE-2023-49842

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpexpertsio Rocket Maintenance Mode & Coming Soon Page allows Stored XSS.This issue affects Rocket Maintenance Mode & Coming Soon Page: from n/a through 4.3.
Max CVSS
5.9
Published
2023-12-14
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49841

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FancyThemes Optin Forms – Simple List Building Plugin for WordPress allows Stored XSS.This issue affects Optin Forms – Simple List Building Plugin for WordPress: from n/a through 1.3.3.
Max CVSS
5.9
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%

CVE-2023-49840

Cross-Site Request Forgery (CSRF) vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%

CVE-2023-49836

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brontobytes Cookie Bar allows Stored XSS.This issue affects Cookie Bar: from n/a through 2.0.
Max CVSS
5.9
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%

CVE-2023-49834

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4.
Max CVSS
8.8
Published
2023-12-17
Updated
2023-12-20
EPSS
0.06%

CVE-2023-49833

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra – WordPress Gutenberg Blocks: from n/a through 2.7.9.
Max CVSS
6.5
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%

CVE-2023-49830

Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.
Max CVSS
9.9
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-49829

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-21
EPSS
0.05%

CVE-2023-49828

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.
Max CVSS
6.5
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%

CVE-2023-49827

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.
Max CVSS
7.1
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%

CVE-2023-49826

Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.
Max CVSS
9.8
Published
2023-12-21
Updated
2023-12-29
EPSS
0.07%

CVE-2023-49825

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.
Max CVSS
8.5
Published
2023-12-20
Updated
2023-12-26
EPSS
0.05%

CVE-2023-49824

Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2.1.1.
Max CVSS
8.8
Published
2023-12-17
Updated
2023-12-20
EPSS
0.06%

CVE-2023-49823

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.6.1.
Max CVSS
6.5
Published
2023-12-15
Updated
2023-12-21
EPSS
0.05%

CVE-2023-49821

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-27
EPSS
0.06%

CVE-2023-49820

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3.
Max CVSS
6.5
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%
50 vulnerabilities found
1 2 3 4 5 6 ...... 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 ...... 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50