Vulnerabilities > Kreado

DATE CVE VULNERABILITY TITLE RISK
2022-06-14 CVE-2021-42675 Unrestricted Upload of File with Dangerous Type vulnerability in Kreado Kreasfero 1.5
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory.
network
low complexity
kreado CWE-434
critical
9.8
2022-03-29 CVE-2021-44581 SQL Injection vulnerability in Kreado Kreasfero 1.5
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.
network
low complexity
kreado CWE-89
7.5