CVE-2020-21809: Nukeviet
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.
Affected products
- Nukeviet Nukeviet: from 4.0.29, up to and including 4.3
Published 2021-07-30. Last modified 2026-06-17.