Filtered by vendor Pocketmanga Subscriptions
Filtered by product Smanga Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-34193 1 Pocketmanga 1 Smanga 2025-02-13 7.5 High
smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.
CVE-2023-36076 1 Pocketmanga 1 Smanga 2024-11-21 9.8 Critical
SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.