Ndk Design maintains a narrowly scoped product portfolio centered on customization and form-handling functionality, with a small but durable vulnerability footprint in its Advanced Customization Fields extension. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ndk Design over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46347CRITICAL In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getP | Oct 25, 2023 | 9.8 | 64 | NO | YES |
CVE-2022-40842CRITICAL ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php. | Nov 22, 2022 | 9.1 | 31 | NO | NO |
CVE-2022-40839HIGH A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data. | Nov 1, 2022 | 7.5 | 27 | NO | NO |
CVE-2022-40841MEDIUM A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into t | Dec 21, 2022 | 6.1 | 24 | NO | NO |
CVE-2022-40840MEDIUM ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php. | Nov 2, 2022 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ndk Design.
Media articles that mention a CVE ID that affects a product developed by Ndk Design — matched by CVE ID, not by vendor name.