Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wp Csv Exporter Project Subscribe
Filtered by product Wp Csv Exporter
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3605 1 Wp Csv Exporter Project 1 Wp Csv Exporter 2022-12-15 N/A 7.8 HIGH
The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability.
CVE-2022-3249 1 Wp Csv Exporter Project 1 Wp Csv Exporter 2022-12-06 N/A 7.2 HIGH
The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks