← Back

Connexion Logs

connexion_logs

Vendor: Floriansimunek • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Floriansimunek
1Connexion Logs
Jun 9, 2025
May 15, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Floriansimunek
1Connexion Logs
Jun 9, 2025
May 15, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks