Webbax develops a narrow line of web application and inventory-management products, including CustomExporter, King-Avis, and MyInventory, that handle user input and sensitive data at the application layer. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, clustering around input-validation deficiencies such as path traversal, SQL injection, and improper data exposure that are endemic to business-application workflows. Defenders should prioritize patches for Webbax products, particularly instances exposed to untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webbax over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30198HIGH Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php. | Jun 12, 2023 | 7.5 | 32 | NO | YES |
CVE-2023-31671CRITICAL PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess(). | Jun 14, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-30199HIGH Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php. | May 19, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-30197HIGH Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by perf | May 31, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-30196HIGH Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php. | May 30, 2023 | 7.5 | 23 | NO | NO |
CVE-2024-25839HIGH An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain se | Mar 3, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-3031MEDIUM Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowing a user knowing the download token to read arbitrary local | Jun 2, 2023 | 4.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webbax.
Media articles that mention a CVE ID that affects a product developed by Webbax — matched by CVE ID, not by vendor name.