Vulnerabilities > Leotheme > Leoblog > 3.1.2

DATE CVE VULNERABILITY TITLE RISK
2023-09-15 CVE-2023-39639 SQL Injection vulnerability in Leotheme Leoblog 3.0.0/3.0.6/3.1.2
LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.
network
low complexity
leotheme CWE-89
critical
9.8