CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Five Minute Webshop Project 1Five Minute Webshop Jun 17, 2026 Jun 8, 2022 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection |
1Five Minute Webshop Project 1Five Minute Webshop Jun 17, 2026 Jun 8, 2022 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection |