Sunnytoo maintains a narrow set of web-facing products including comment systems, blog search, and URL management utilities, with the durable vulnerability signal concentrated on SQL injection weaknesses in input-handling and database-query construction. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sunnytoo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43985CRITICAL SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component. | Jan 19, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-28388CRITICAL SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information | Mar 14, 2024 | 9.8 | 24 | NO | NO |
CVE-2023-46348CRITICAL SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and S | Dec 14, 2023 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sunnytoo.
Media articles that mention a CVE ID that affects a product developed by Sunnytoo — matched by CVE ID, not by vendor name.