YouGina

3 exploits Active since Jul 2021
CVE-2021-35042 NOMISEC CRITICAL WORKING POC
Django <3.1.13, <3.2.5 - SQL Injection
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
13 stars
CVSS 9.8
CVE-2022-28346 NOMISEC CRITICAL WORKING POC
Django <4.0.4 - SQL Injection
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.
2 stars
CVSS 9.8
CVE-2023-32243 NOMISEC CRITICAL WORKING POC
Wpdeveloper Essential Addons For Elementor - Authentication Bypass
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
CVSS 9.8