Vulnerabilities > BUY Addons

DATE CVE VULNERABILITY TITLE RISK
2024-01-05 CVE-2023-50027 SQL Injection vulnerability in Buy-Addons Bazoom Magnifier
SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.
network
low complexity
buy-addons CWE-89
critical
9.8
2023-12-14 CVE-2023-48925 SQL Injection vulnerability in Buy-Addons Bavideotab
SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().
network
low complexity
buy-addons CWE-89
critical
9.8