Vulnerabilities > Icegram > Icegram Express > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-12 | CVE-2024-4845 | SQL Injection vulnerability in Icegram Express The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 8.8 |
2023-10-20 | CVE-2023-5414 | Path Traversal vulnerability in Icegram Express The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. | 7.2 |