Vulnerabilities > Coinmarketstats

DATE CVE VULNERABILITY TITLE RISK
2023-05-08 CVE-2022-4118 Unspecified vulnerability in Coinmarketstats Bitcoin / Altcoin Payment Gateway for Woocommerce
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users
network
low complexity
coinmarketstats
critical
9.8
2021-10-04 CVE-2021-24679 Cross-site Scripting vulnerability in Coinmarketstats Bitcoin / Altcoin Payment Gateway for Woocommerce
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
network
low complexity
coinmarketstats CWE-79
6.1