Vulnerabilities > Soflyy > High

DATE CVE VULNERABILITY TITLE RISK
2022-06-13 CVE-2022-1800 SQL Injection vulnerability in Soflyy Export ANY Wordpress Data to Xml/Csv
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
network
low complexity
soflyy CWE-89
7.2
2019-08-20 CVE-2015-9330 SQL Injection vulnerability in Soflyy WP ALL Import
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
network
low complexity
soflyy CWE-89
7.5