SALESmanago & Leadoo
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-10835 | 0.00 | — | 0.00 | Jun 26, 2026 | The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal… | |||
| CVE-2026-54822 | 0.00 | — | 0.00 | Jun 25, 2026 | Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. |
- CVE-2026-10835Jun 26, 2026risk 0.00cvss —epss 0.00
The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal…
- CVE-2026-54822Jun 25, 2026risk 0.00cvss —epss 0.00
Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.