Datainterlock
Datainterlock Note Press: vulnerabilidades y CVE
Datainterlock Note Press tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-1690 | Baja (2.7) | 0.80% | — | 8 jun 2022 | The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection |
| CVE-2022-1689 | Baja (2.7) | 0.80% | — | 8 jun 2022 | The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection |
| CVE-2022-1688 | Baja (2.7) | 0.80% | — | 8 jun 2022 | The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections |
| CVE-2017-18548 | Crítica (9.8) | 1.8% | — | 16 ago 2019 | The note-press plugin before 0.1.2 for WordPress has SQL injection. |