Leotheme develops a small portfolio of web application and blogging modules, with observed vulnerabilities concentrating in products such as LeoBlog and LeoCustomAjax around SQL injection flaws in input handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leotheme over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30150CRITICAL PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php. | Jun 14, 2023 | 9.8 | 40 | NO | YES |
CVE-2023-39639CRITICAL LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs. | Sep 15, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leotheme.
Media articles that mention a CVE ID that affects a product developed by Leotheme — matched by CVE ID, not by vendor name.