Products

Showing 3 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
leotheme vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.

CWE-79Sep 20, 2024
CVSS6.1v3.1EPSS0.353%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SQL injection vulnerability in LeoTheme's Ap Page Builder

Ap Page Builder, in versions lower than 1.7.8.2, could allow a remote attacker to send a specially crafted SQL query to the product_one_img parameter to retrieve the information stored in the database.

CWE-89Jul 18, 2023
CVSS7.5v3.1EPSS0.756%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

leotheme leocustomajax Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

CWE-89Jun 14, 20231 related artifact
CVSS9.8v3.1EPSS3.85%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX