| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-23712 | WordPress User Meta Manager Plugin <= 3.4.9 is vulnerable to Cross Site Request Forgery (CSRF) | User Meta Manager | User Meta Manager | Medium | 5.4 | 2023-05-22 08:27:37 | Deep Dive |
| CVE-2023-30780 | WordPress User IP and Location Plugin <= 2.2 is vulnerable to Cross Site Scripting (XSS) | TheGuideX | User IP and Location | Medium | 6.5 | 2023-05-18 10:02:59 | Deep Dive |
| CVE-2023-2548 | RegistrationMagic <= 5.2.0.5 - Authenticated (Admin+) Insecure Direct Object Reference to Arbitrary User Password Change | metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Medium | 6.6 | 2023-05-16 08:40:02 | Deep Dive |
| CVE-2023-2499 | RegistrationMagic <= 5.2.1.0 - Authentication Bypass | metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Critical | 9.8 | 2023-05-16 08:40:01 | Deep Dive |
| CVE-2023-20046 | Cisco StarOS 安全漏洞 | Cisco | Cisco ASR 5000 Series Software | High | 8.8 | 2023-05-09 13:06:11 | Deep Dive |
| CVE-2023-25786 | WordPress Eyes Only: User Access Shortcode Plugin <= 1.8.2 is vulnerable to Cross Site Scripting (XSS) | Thom Stark | Eyes Only: User Access Shortcode | Medium | 5.9 | 2023-05-03 10:47:20 | Deep Dive |
| CVE-2023-2297 | Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset Mechanism | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Critical | 9.8 | 2023-04-26 23:30:18 | Deep Dive |
| CVE-2023-22718 | WordPress User Meta Manager Plugin <= 3.4.9 is vulnerable to Cross Site Scripting (XSS) | Jason Lau | User Meta Manager | High | 7.1 | 2023-04-23 09:27:13 | Deep Dive |
| CVE-2023-21997 | Oracle User Management 安全漏洞 | Oracle Corporation | User Management | Medium | 4.3 | 2023-04-18 19:54:44 | Deep Dive |
| CVE-2023-23987 | WordPress User Registration Plugin <= 2.3.0 is vulnerable to Cross Site Scripting (XSS) | WPEverest | User Registration | Medium | 5.9 | 2023-04-06 05:22:56 | Deep Dive |
| CVE-2022-41633 | WordPress Community by PeepSo Plugin <= 6.0.2.0 is vulnerable to Cross Site Request Forgery (CSRF) | PeepSo | Community by PeepSo – Social Network, Membership, Registration, User Profiles | Medium | 5.4 | 2023-04-04 11:12:16 | Deep Dive |
| CVE-2023-0820 | User Role by BestWebSoft < 1.6.7 - Privilege Escalation via CSRF | Unknown | User Role by BestWebSoft | 高危 | - | 2023-04-03 14:38:26 | Deep Dive |
| CVE-2022-47444 | WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS) | ProfilePress Membership Team | Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | High | 7.1 | 2023-03-29 12:35:45 | Deep Dive |
| CVE-2020-36666 | Multiple e-plugins - Subscriber+ Privilege Escalation | Unknown | directory-pro | 高危 | - | 2023-03-27 15:37:27 | Deep Dive |
| CVE-2022-38971 | WordPress BuddyForms Plugin <= 2.7.5 is vulnerable to Cross Site Scripting (XSS) | ThemeKraft | Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions | Medium | 4.7 | 2023-03-16 08:49:16 | Deep Dive |
| CVE-2023-25968 | WordPress Client Portal – Private user pages and login Plugin <= 1.1.8 is vulnerable to Cross Site Request Forgery (CSRF) | Cozmoslabs, Madalin Ungureanu, Antohe Cristian | Client Portal – Private user pages and login | Medium | 4.3 | 2023-03-15 10:20:38 | Deep Dive |
| CVE-2015-10093 | Mark User as Spammer Plugin plugin.php user_row_actions cross site scripting | - | Mark User as Spammer Plugin | Low | 2.6 | 2023-03-06 06:31:04 | Deep Dive |
| CVE-2023-0043 | Custom Add User <= 2.0.2 - Reflected Cross-Site Scripting | Unknown | Custom Add User | 中危 | - | 2023-02-27 15:24:42 | Deep Dive |
| CVE-2022-4550 | User Activity <= 1.0.1 - IP Spoofing | Unknown | User Activity | 高危 | - | 2023-02-27 15:24:37 | Deep Dive |
| CVE-2023-0814 | Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Sensitive Information Disclosure via Shortcode | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Medium | 6.5 | 2023-02-14 01:13:13 | Deep Dive |