prestashopmodules kayıtları
prestashopmodules üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-359 Exposure of Private Personal Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-552 Files or Directories Accessible to External Parties1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-50028İstismar yok | In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL prestashopmodules · sliding cart block · CWE-89 | Kritik9,8 | — | %0,7 | 19 Oca 2024 |
39İzleyin | CVE-2024-33268İstismar yok | SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::addCWE-89 | Kritik9,8 | — | %0,5 | 29 Nis 2024 |
39İzleyin | CVE-2024-33836İstismar yok | In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .CWE-434 | Kritik9,8 | — | %0,5 | 19 Haz 2024 |
30İzleyin | CVE-2024-2759İstismar yok | Improper access control in Apaczka plugin for PrestaShopalsendo sp. z o. o. · apaczka · CWE-552 | Yüksek7,5 | — | %0,6 | 4 Nis 2024 |
30İzleyin | CVE-2024-36682İstismar yok | In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SCWE-359 | Yüksek7,5 | — | %0,4 | 24 Haz 2024 |
- CVE-2023-5002839İzleyin
In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL
KritikCVSS 9,8İstismar yokEPSS %1prestashopmodules · sliding cart block19 Oca 2024
- CVE-2024-3326839İzleyin
SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::add
KritikCVSS 9,8İstismar yokEPSS %129 Nis 2024
- CVE-2024-3383639İzleyin
In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .
KritikCVSS 9,8İstismar yokEPSS %019 Haz 2024
- CVE-2024-275930İzleyin
Improper access control in Apaczka plugin for PrestaShop
YüksekCVSS 7,5İstismar yokEPSS %1alsendo sp. z o. o. · apaczka4 Nis 2024
- CVE-2024-3668230İzleyin
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while S
YüksekCVSS 7,5İstismar yokEPSS %024 Haz 2024