Vulnerabilities > Orangelab

DATE CVE VULNERABILITY TITLE RISK
2023-10-20 CVE-2022-2441 Cross-Site Request Forgery (CSRF) vulnerability in Orangelab Imagemagick Engine
The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5.
network
low complexity
orangelab CWE-352
8.8
2023-02-10 CVE-2022-3568 Cross-Site Request Forgery (CSRF) vulnerability in Orangelab Imagemagick Engine
The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and including 1.7.5.
network
low complexity
orangelab CWE-352
8.8