Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Defender Security | 0 ~ 4.1.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page) | https://github.com/Cappricio-Securities/CVE-2023-5089 | POC Details |
| 2 | The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5089.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-4950 | Funnelforms Free < 3.4 Unauthenticated Stored Cross-Site Scripting | |
| CVE-2023-3154 | NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization | |
| CVE-2023-4691 | Bookly < 22.4 - Admin+ SQLi | |
| CVE-2023-4783 | Magee Shortcodes <= 2.1.1 - Contributor+ Stored XSS via shortcode | |
| CVE-2023-4795 | Testimonial Slider Shortcode < 1.1.9 - Contributor+ Stored XSS | |
| CVE-2023-4687 | PageLayer < 1.7.7 - Unauthenticated Stored XSS | |
| CVE-2023-4388 | EventON < 2.2 - Admin+ Stored XSS | |
| CVE-2023-5167 | User Activity Log Pro < 2.3.4 - Unauthenticated Stored Cross-Site Scripting via User Agent | |
| CVE-2023-4776 | WPSchoolPress < 2.2.5 - Teacher+ SQLi | |
| CVE-2023-4643 | Enable Media Replace < 4.1.3 - Author+ PHP Object Injection | |
| CVE-2023-4805 | Tutor LMS < 2.3.0 - Subscriber+ Stored Cross-Site Scripting | |
| CVE-2023-5087 | PageLayer < 1.7.8 - Author+ Stored XSS | |
| CVE-2023-4862 | File Manager Pro < 1.8.1 - Admin+ Stored Cross-Site Scripting | |
| CVE-2023-4819 | Shared Files < 1.7.6 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2023-5177 | Vrm 360 3D Model Viewer <= 1.2.1 - Full Path Disclosure | |
| CVE-2023-4971 | Weaver Xtreme Theme Support < 6.3.1 - Admin+ PHP Object Injection | |
| CVE-2023-4290 | WP Matterport Shortcode < 2.1.7 - Reflected XSS | |
| CVE-2023-4620 | Booking Calendar < 9.7.3.1 - Unauthenticated Stored XSS | |
| CVE-2023-3392 | Read More & Accordion < 3.2.7 - Admin+ PHP Object Injection | |
| CVE-2023-4827 | File Manager Pro < 1.8 - Remote Code Execution via CSRF |
Showing top 20 of 40 CVEs. View all on vendor page → →
No comments yet