VYPR
Vendor

Webbax

Products
9
CVEs
8
Across products
9
Status
Private

Products

9

Recent CVEs

8
  • CVE-2024-33275CriApr 30, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components.

  • CVE-2023-31671CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().

  • CVE-2023-30198HigJun 12, 2023
    risk 0.52cvss 7.5epss 0.06

    Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.

  • CVE-2024-25839HigMar 3, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information.

  • CVE-2023-30197HigMay 31, 2023
    risk 0.49cvss 7.5epss 0.01

    Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack.

  • CVE-2023-30196HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.

  • CVE-2023-30199HigMay 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php.

  • CVE-2023-3031MedJun 2, 2023
    risk 0.32cvss 4.9epss 0.01

    Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowing a user knowing the download token to read arbitrary local files.This issue affects King-Avis: before 17.3.15.