Vulnerabilities (CVE)

Filtered by vendor Kohsei-works Subscribe
Filtered by product Yes\/no Chart
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24360 1 Kohsei-works 1 Yes\/no Chart 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks