Vulnerabilities (CVE)

Filtered by vendor Ketchup Restaurant Reservations Project Subscribe
Filtered by product Ketchup Restaurant Reservations
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2754 1 Ketchup Restaurant Reservations Project 1 Ketchup Restaurant Reservations 2024-11-21 N/A 9.8 CRITICAL
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
CVE-2022-2753 1 Ketchup Restaurant Reservations Project 1 Ketchup Restaurant Reservations 2024-11-21 N/A 6.1 MEDIUM
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made