Security Vulnerabilities, CVEs
CVE-2023-48772
Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation: from n/a through 2.0.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-22
EPSS
0.06%
CVE-2023-48771
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno "Aesqe" Babic File Gallery allows Reflected XSS.This issue affects File Gallery: from n/a through 1.8.5.4.
Max CVSS
7.1
Published
2023-12-14
Updated
2023-12-19
EPSS
0.05%
CVE-2023-48770
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nima Saberi Aparat allows Stored XSS.This issue affects Aparat: from n/a through 1.7.1.
Max CVSS
6.5
Published
2023-12-14
Updated
2023-12-19
EPSS
0.05%
CVE-2023-48769
Cross-Site Request Forgery (CSRF) vulnerability in Blue Coral Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back.This issue affects Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back: from n/a through 2.3.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-22
EPSS
0.06%
CVE-2023-48768
Cross-Site Request Forgery (CSRF) vulnerability in CodeAstrology Team Quantity Plus Minus Button for WooCommerce by CodeAstrology.This issue affects Quantity Plus Minus Button for WooCommerce by CodeAstrology: from n/a through 1.1.9.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-22
EPSS
0.06%
CVE-2023-48767
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raghu Goriya MyTube PlayList allows Reflected XSS.This issue affects MyTube PlayList: from n/a through 2.0.3.
Max CVSS
7.1
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%
CVE-2023-48766
Cross-Site Request Forgery (CSRF) vulnerability in SVGator SVGator – Add Animated SVG Easily.This issue affects SVGator – Add Animated SVG Easily: from n/a through 1.2.4.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%
CVE-2023-48765
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Till Krüss Email Address Encoder allows Stored XSS.This issue affects Email Address Encoder: from n/a through 1.0.22.
Max CVSS
6.5
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-48764
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.
Max CVSS
7.6
Published
2023-12-19
Updated
2023-12-28
EPSS
0.05%
CVE-2023-48762
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%
CVE-2023-48756
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor allows Reflected XSS.This issue affects JetBlocks For Elementor: from n/a through 1.3.8.
Max CVSS
7.1
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%
CVE-2023-48755
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.
Max CVSS
8.8
Published
2023-12-18
Updated
2023-12-20
EPSS
0.06%
CVE-2023-48754
Cross-Site Request Forgery (CSRF) vulnerability in Wap Nepal Delete Post Revisions In WordPress allows Cross Site Request Forgery.This issue affects Delete Post Revisions In WordPress: from n/a through 4.6.
Max CVSS
8.8
Published
2023-11-30
Updated
2023-12-06
EPSS
0.06%
CVE-2023-48752
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Happyforms Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms allows Reflected XSS.This issue affects Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms: from n/a through 1.25.9.
Max CVSS
7.1
Published
2023-11-30
Updated
2023-12-06
EPSS
0.05%
CVE-2023-48751
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects Participants Database: from n/a through 2.5.5.
Max CVSS
8.8
Published
2023-12-19
Updated
2023-12-22
EPSS
0.06%
CVE-2023-48749
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: from n/a through 2.0.2.
Max CVSS
6.5
Published
2023-11-30
Updated
2023-12-06
EPSS
0.05%
CVE-2023-48748
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Reflected XSS.This issue affects Salient Core: from n/a through 2.0.2.
Max CVSS
7.1
Published
2023-11-30
Updated
2023-12-06
EPSS
0.05%
CVE-2023-48746
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles allows Reflected XSS.This issue affects Community by PeepSo – Social Network, Membership, Registration, User Profiles: from n/a through 6.2.6.0.
Max CVSS
7.1
Published
2023-11-30
Updated
2023-12-06
EPSS
0.05%
CVE-2023-48744
Cross-Site Request Forgery (CSRF) vulnerability in Offshore Web Master Availability Calendar allows Cross Site Request Forgery.This issue affects Availability Calendar: from n/a through 1.2.6.
Max CVSS
8.8
Published
2023-11-30
Updated
2023-12-05
EPSS
0.06%
CVE-2023-48743
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Menard Simply Exclude allows Reflected XSS.This issue affects Simply Exclude: from n/a through 2.0.6.6.
Max CVSS
6.1
Published
2023-11-30
Updated
2023-12-05
EPSS
0.05%
CVE-2023-48742
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LicenseManager License Manager for WooCommerce license-manager-for-woocommerce allows SQL Injection.This issue affects License Manager for WooCommerce: from n/a through 2.2.10.
Max CVSS
7.6
Published
2023-11-30
Updated
2023-12-05
EPSS
0.05%
CVE-2023-48741
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI ChatBot: from n/a through 4.7.8.
Max CVSS
7.6
Published
2023-12-19
Updated
2023-12-22
EPSS
0.05%
CVE-2023-48738
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.
Max CVSS
9.8
Published
2023-12-19
Updated
2023-12-28
EPSS
0.08%
CVE-2023-48737
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PT Trijaya Digital Grup TriPay Payment Gateway allows Stored XSS.This issue affects TriPay Payment Gateway: from n/a through 3.2.7.
Max CVSS
5.9
Published
2023-11-30
Updated
2023-12-05
EPSS
0.05%
CVE-2023-48736
In International Color Consortium DemoIccMAX 3e7948b, CIccCLUT::Interp2d in IccTagLut.cpp in libSampleICC.a has an out-of-bounds read.
Max CVSS
6.5
Published
2023-11-18
Updated
2023-11-24
EPSS
0.05%