Vulnerabilities > Tribulant > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-08-22 CVE-2018-20987 Deserialization of Untrusted Data vulnerability in Tribulant Newsletters
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
network
low complexity
tribulant CWE-502
critical
9.8
2019-04-15 CVE-2018-18018 SQL Injection vulnerability in Tribulant Slideshow Gallery 1.6.8
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
network
low complexity
tribulant CWE-89
critical
9.8