Ndkdesign develops e-commerce and website customization plugins, with observed vulnerabilities concentrating in products such as the Advanced Customization Fields and Stepping Pack extensions. The durable signal centers on SQL injection weaknesses in input handling across these products, which are typical of web-facing plugins that process user-supplied data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ndkdesign over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46347CRITICAL In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getP | Oct 25, 2023 | 9.8 | 64 | NO | YES |
CVE-2022-40842CRITICAL ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php. | Nov 22, 2022 | 9.1 | 31 | NO | NO |
CVE-2022-40839HIGH A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data. | Nov 1, 2022 | 7.5 | 27 | NO | NO |
CVE-2022-40841MEDIUM A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into t | Dec 21, 2022 | 6.1 | 24 | NO | NO |
CVE-2022-40840MEDIUM ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php. | Nov 2, 2022 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ndkdesign.
Media articles that mention a CVE ID that affects a product developed by Ndkdesign — matched by CVE ID, not by vendor name.