boostifythemes CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

boostifythemes vulnerability overview

Aggregates CVE and security vulnerability intelligence across all boostifythemes-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk sql injection and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-24297 The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability. [email protected] 6.1 0.36% 2021-05-24 2024-11-21
CVE-2021-24314 The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue [email protected] 9.8 1.02% 2021-05-17 2024-11-21
CVE-2021-24235 The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue. [email protected] 6.1 43.82% 2021-04-22 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence