Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Five Minute Webshop Project Subscribe
Filtered by product Five Minute Webshop
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1686 1 Five Minute Webshop Project 1 Five Minute Webshop 2022-06-15 4.0 MEDIUM 2.7 LOW
The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection
CVE-2022-1685 1 Five Minute Webshop Project 1 Five Minute Webshop 2022-06-15 4.0 MEDIUM 4.9 MEDIUM
The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection