VYPR
Vendor

SunnyToo

Products
4
CVEs
3
Across products
4
Status
Private

Products

4

Recent CVEs

3
  • CVE-2024-28388CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.

  • CVE-2023-43985CriJan 19, 2024
    risk 0.64cvss 9.8epss 0.01

    SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component.

  • CVE-2023-46348CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.