Promokit's vulnerability footprint is concentrated in its theme-settings product, a narrowly scoped component within its product line. The observed weakness centers on SQL injection, an input-handling class endemic to database-connected applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Promokit over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-36678CRITICAL In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that ca | Jun 19, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Promokit.
Media articles that mention a CVE ID that affects a product developed by Promokit — matched by CVE ID, not by vendor name.