posthemes records
2 published records for vendor posthemes.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-30189No exploit | Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().posthemes · posstaticblocks · CWE-89 | Critical9.8 | — | 0.8% | May 16, 2023 |
39Monitor | CVE-2023-45379No exploit | In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection.posthemes · posrotatorimg · CWE-89 | Critical9.8 | — | 0.5% | Oct 19, 2023 |
- CVE-2023-3018939Monitor
Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
CriticalCVSS 9.8No exploitEPSS 1%posthemes · posstaticblocksMay 16, 2023
- CVE-2023-4537939Monitor
In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection.
CriticalCVSS 9.8No exploitEPSS 1%posthemes · posrotatorimgOct 19, 2023