Blmodules develops data-feed products, primarily CSV Feeds Pro and XML Feeds Pro, where the durable signal centers on application-layer input-handling flaws including SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blmodules over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46356CRITICAL In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL | Oct 31, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-39643CRITICAL Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds(). | Sep 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-46355MEDIUM In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control | Nov 27, 2023 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blmodules.
Media articles that mention a CVE ID that affects a product developed by Blmodules — matched by CVE ID, not by vendor name.