Filtered by vendor Leotheme Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-42697 1 Leotheme 1 Leo Product Search Module 2024-09-26 6.1 Medium
Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.
CVE-2023-39639 1 Leotheme 1 Leoblog 2024-09-25 9.8 Critical
LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.
CVE-2023-30150 1 Leotheme 1 Leocustomajax 2024-08-02 9.8 Critical
PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.