Vulnerabilities > Simple Subscription Website Project

DATE CVE VULNERABILITY TITLE RISK
2022-03-21 CVE-2022-26283 SQL Injection vulnerability in Simple Subscription Website Project Simple Subscription Website 1.0
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint.
network
low complexity
simple-subscription-website-project CWE-89
critical
9.8
2021-11-03 CVE-2021-43140 SQL Injection vulnerability in Simple Subscription Website Project Simple Subscription Website 1.0
SQL Injection vulnerability exists in Sourcecodester.
network
low complexity
simple-subscription-website-project CWE-89
critical
9.8
2021-11-03 CVE-2021-43141 Cross-site Scripting vulnerability in Simple Subscription Website Project Simple Subscription Website 1.0
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.
6.1