Five Minute Webshop Project maintains a focused e-commerce platform that presents a narrow but notable attack surface, with the durable signal centered on SQL-injection vulnerabilities in the product's database-interaction layer. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Five Minute Webshop Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboa | Jun 8, 2022 | 2.7 | 16 | NO | NO |
CVE-2022-1685MEDIUM The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admi | Jun 8, 2022 | 4.9 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Five Minute Webshop Project.
Media articles that mention a CVE ID that affects a product developed by Five Minute Webshop Project — matched by CVE ID, not by vendor name.