Vulnerabilities (CVE)

Filtered by vendor Sunnytoo Subscribe
Filtered by product Product Comments
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28388 1 Sunnytoo 1 Product Comments 2025-09-18 N/A 9.8 CRITICAL
SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.