Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ays-pro Subscribe
Filtered by product Popup Box
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24460 1 Ays-pro 1 Popup Box 2021-08-10 6.5 MEDIUM 8.8 HIGH
The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVE-2021-24458 1 Ays-pro 1 Popup Box 2021-08-10 6.5 MEDIUM 8.8 HIGH
The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard