leotheme Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with leotheme products.
Products
- Ap Page Builder1 vulnerability
- leo_product_search_module1 vulnerability
- leocustomajax1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-42697MEDIUM | Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function. CWE-79Sep 20, 2024 | CVSS6.1v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3743HIGH | SQL injection vulnerability in LeoTheme's Ap Page BuilderAp Page Builder, in versions lower than 1.7.8.2, could allow a remote attacker to send a specially crafted SQL query to the product_one_img parameter to retrieve the information stored in the database. CWE-89Jul 18, 2023 | CVSS7.5v3.1 | EPSS0.756% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30150CRITICAL | leotheme leocustomajax Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php. | CVSS9.8v3.1 | EPSS3.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |