Vulnerabilities > Catalystconnect

DATE CVE VULNERABILITY TITLE RISK
2023-08-10 CVE-2022-44629 Cross-site Scripting vulnerability in Catalystconnect Catalyst Connect Zoho CRM Client Portal 1.0/1.1/2.0.0
Auth.
network
low complexity
catalystconnect CWE-79
4.8
2023-06-27 CVE-2023-0588 Unspecified vulnerability in Catalystconnect Zoho CRM Client Portal
The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.
network
low complexity
catalystconnect
6.1