Vulnerabilities > Kainelabs > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-37494 Unspecified vulnerability in Kainelabs Youzify
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5.
network
low complexity
kainelabs
8.8
2024-06-20 CVE-2024-4742 SQL Injection vulnerability in Kainelabs Youzify
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
kainelabs CWE-89
8.8