VYPR
Vendor

Leotheme

Products
3
CVEs
3
Across products
3
Status
Private

Products

3

Recent CVEs

3
  • CVE-2023-39639CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.

  • CVE-2023-3743HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Ap Page Builder, in versions lower than 1.7.8.2, could allow a remote attacker to send a specially crafted SQL query to the product_one_img parameter to retrieve the information stored in the database.

  • CVE-2024-42697MedSep 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.