armandofiore CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

armandofiore vulnerability overview

Aggregates CVE and security vulnerability intelligence across all armandofiore-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk csrf and vendor risk sql injection, with potential vendor impact data exposure across vendor surface software deployment and vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-4445 The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. [email protected] 9.8 4.73% 2023-02-13 2025-10-07
CVE-2022-4553 The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables [email protected] 4.3 0.09% 2023-01-30 2025-10-07
CVE-2022-4552 The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack [email protected] 6.1 0.13% 2023-01-30 2025-10-07
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence