Vulnerabilities > Boostifythemes

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2021-24297 Cross-site Scripting vulnerability in Boostifythemes Goto 2.0
The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
4.3
2021-05-17 CVE-2021-24314 SQL Injection vulnerability in Boostifythemes Goto 2.0
The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue
network
low complexity
boostifythemes CWE-89
7.5
2021-04-22 CVE-2021-24235 Cross-site Scripting vulnerability in Boostifythemes Goto
The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.
network
low complexity
boostifythemes CWE-79
6.1