Filtered by vendor Xllentech
Subscribe
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24341 | 1 Xllentech | 1 English Islamic Calendar | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection. |