Vulnerabilities > Promokit > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-06-19 CVE-2024-36678 SQL Injection vulnerability in Promokit PK Themesettings 1.8.8
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection.
network
low complexity
promokit CWE-89
critical
9.8