Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Simple Subscription Website Project Subscribe
Filtered by product Simple Subscription Website
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26283 1 Simple Subscription Website Project 1 Simple Subscription Website 2022-03-29 7.5 HIGH 9.8 CRITICAL
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
CVE-2021-43141 1 Simple Subscription Website Project 1 Simple Subscription Website 2021-11-23 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.
CVE-2021-43140 1 Simple Subscription Website Project 1 Simple Subscription Website 2021-11-16 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.