Skip to content
Noroxi

posthemes records

2 published records for vendor posthemes.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 23

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

2 records
  • Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().

    CriticalCVSS 9.8No exploitEPSS 1%

    posthemes · posstaticblocksMay 16, 2023

  • In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection.

    CriticalCVSS 9.8No exploitEPSS 1%

    posthemes · posrotatorimgOct 19, 2023