Vulnerabilities (CVE)

Filtered by vendor Carts.guru Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-39642 1 Carts.guru 1 Cartsguru 2023-12-10 N/A 9.8 CRITICAL
Carts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::display().
CVE-2019-12241 1 Carts.guru 1 Carts Guru 2023-12-10 7.5 HIGH 9.8 CRITICAL
The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.