Vulnerabilities > Invisioncommunity > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-06-07 CVE-2024-30163 SQL Injection vulnerability in Invisioncommunity
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries.
network
low complexity
invisioncommunity CWE-89
critical
9.8