NA - CVE-2023-5336 - The iPanorama 360 – WordPress Virtual Tour...
The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient...
NA - CVE-2023-5638 - The Booster for WooCommerce plugin for...
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode in versions up to, and including, 7.1.2 due to insufficient input...
NA - CVE-2023-5639 - The Team Showcase plugin for WordPress is...
The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tmfshortcode' shortcode in all versions up to, and including, 2.1 due to...
NA - CVE-2023-46228 - zchunk before 1.3.2 has multiple integer...
zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.
NA - CVE-2023-46229 - LangChain before 0.0.317 allows SSRF via...
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
NA - CVE-2023-5204 - The ChatBot plugin for WordPress is vulnerable...
The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack...
NA - CVE-2023-5212 - The AI ChatBot plugin for WordPress is...
The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9. This makes it possible for authenticated attackers with subscriber privileges...
NA - CVE-2023-5241 - The AI ChatBot for WordPress is vulnerable to...
The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level...
NA - CVE-2023-5254 - The ChatBot plugin for WordPress is vulnerable...
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated...