webbax CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

webbax vulnerability overview

Aggregates CVE and security vulnerability intelligence across all webbax-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk path handling and vendor risk sql injection and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-25839 An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information. [email protected] 7.5 0.09% 2024-03-03 2025-05-15
CVE-2023-31671 PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess(). [email protected] 9.8 0.07% 2023-06-14 2025-01-06
CVE-2023-30198 Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php. [email protected] 7.5 20.73% 2023-06-12 2025-01-06
CVE-2023-3031 Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowing a user knowing the download token to read arbitrary local files.This issue affects King-Avis: before 17.3.15. [email protected] 4.9 0.46% 2023-06-02 2024-11-21
CVE-2023-30197 Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack. [email protected] 7.5 0.40% 2023-05-31 2025-01-09
CVE-2023-30196 Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php. [email protected] 7.5 0.23% 2023-05-30 2025-01-13
CVE-2023-30199 Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php. [email protected] 7.5 0.44% 2023-05-19 2025-01-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence