LiveActive security incident?Get immediate response
CVE archive

November 2023

Browse CVE records published in November 2023, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2410 matching CVEs · Page 3 of 49.

Medium · CVSS 4.3

CVE-2023-47757: WordPress AWeber Plugin <= 7.3.9 is vulnerable to Broken Access Control

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth allows Accessing Functionality Not Properly Constrained by ACLs, Cross-Site Request Forgery.This issue affects AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth: from n/a through 7.3.9.

Published Nov 17, 2023 · Updated Apr 28, 2026