Boostifythemes Goto vulnerabilities
3 known vulnerabilities affecting boostifythemes/goto.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2021-24235P3MEDIUMCVSS 6.1PoCfixed in 2.02021-04-22
CVE-2021-24235 [MEDIUM] CWE-79 CVE-2021-24235: The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on i
The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.
nvd
CVE-2021-24314P3CRITICALCVSS 9.8fixed in 2.1≥ 2.1, < 2.12021-05-17
CVE-2021-24314 [CRITICAL] CWE-89 CVE-2021-24314: The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter
The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue
nvd
CVE-2021-24297P4MEDIUMCVSS 6.1fixed in 2.12021-05-24
CVE-2021-24297 [MEDIUM] CWE-79 CVE-2021-24297: The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in i
The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
nvd