← Back

Mitchelllevy

mitchelllevy

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Ahathat
ahathat

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mitchelllevy
1Ahathat
Jun 17, 2026
May 15, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.
1Mitchelllevy
1Ahathat
Jun 17, 2026
Jan 2, 2025
N/A· v4
4.7 MEDIUM· v3
N/A· v2
The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers