Vulnerabilities (CVE)

Filtered by vendor Kreado Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42675 1 Kreado 1 Kreasfero 2022-06-22 7.5 HIGH 9.8 CRITICAL
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
CVE-2021-44581 1 Kreado 1 Kreasfero 2022-04-04 5.0 MEDIUM 7.5 HIGH
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.