CVE-2023-40215

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Demonisblack demon image annotation allows SQL Injection.This issue affects demon image annotation: from n/a through 5.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:superwhite:demon_image_annotation:*:*:*:*:*:wordpress:*:*

History

29 Apr 2026, 10:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 7.6

28 Apr 2026, 19:21

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Demonisblack demon image annotation allows SQL Injection.This issue affects demon image annotation: from n/a through 5.1. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Demonisblack demon image annotation allows SQL Injection.This issue affects demon image annotation: from n/a through 5.1.

21 Nov 2024, 08:19

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/demon-image-annotation/wordpress-demon-image-annotation-plugin-5-1-sql-injection-vulnerability?_s_id=cve - Third Party Advisory () https://patchstack.com/database/vulnerability/demon-image-annotation/wordpress-demon-image-annotation-plugin-5-1-sql-injection-vulnerability?_s_id=cve - Third Party Advisory

09 Nov 2023, 20:07

Type Values Removed Values Added
References (MISC) https://patchstack.com/database/vulnerability/demon-image-annotation/wordpress-demon-image-annotation-plugin-5-1-sql-injection-vulnerability?_s_id=cve - (MISC) https://patchstack.com/database/vulnerability/demon-image-annotation/wordpress-demon-image-annotation-plugin-5-1-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
First Time Superwhite demon Image Annotation
Superwhite
CPE cpe:2.3:a:superwhite:demon_image_annotation:*:*:*:*:*:wordpress:*:*

04 Nov 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-04 00:15

Updated : 2026-04-29 10:16


NVD link : CVE-2023-40215

Mitre link : CVE-2023-40215

CVE.ORG link : CVE-2023-40215


JSON object : View

Products Affected

superwhite

  • demon_image_annotation
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')