Filtered by vendor Kreado Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-44581 1 Kreado 1 Kreasfero 2024-08-04 7.5 High
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.
CVE-2021-42675 1 Kreado 1 Kreasfero 2024-08-04 9.8 Critical
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.