Filtered by vendor Prestashopmodules Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-33268 1 Prestashopmodules 1 Mdgiftproduct 2024-11-21 9.8 Critical
SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::addGiftToCart method.
CVE-2024-2759 1 Prestashopmodules 1 Apaczka 2024-11-21 7.5 High
Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates without authentication.This issue affects Apaczka plugin for PrestaShop from v1 through v4.
CVE-2023-50028 1 Prestashopmodules 1 Sliding Cart Block 2024-11-21 9.8 Critical
In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection.