Vulnerabilities > Badgeos > High

DATE CVE VULNERABILITY TITLE RISK
2023-05-25 CVE-2022-41987 Unspecified vulnerability in Badgeos
Cross-Site Request Forgery (CSRF) vulnerability in LearningTimes BadgeOS plugin <= 3.7.1.6 versions.
network
low complexity
badgeos
8.8
2022-09-19 CVE-2022-2958 Unspecified vulnerability in Badgeos Badgos
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
network
low complexity
badgeos
8.8