📦 Canto

by Canto

🔍 What is Canto?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-4936

CRITICAL CVSS 9.8 Jun 14, 2024

The Canto WordPress plugin has a Remote File Inclusion vulnerability in all versions up to 3.0.8 that allows unauthenticated attackers to include remote files on the server, potentially leading to rem...

CVE-2024-25096

CRITICAL CVSS 10.0 Apr 3, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress sites running the vulnerable Canto plugin. It affects all WordPress installations using Canto plugin versions...

CVE-2023-3452

CRITICAL CVSS 9.8 Aug 12, 2023

The Canto plugin for WordPress versions up to 3.0.4 contains a Remote File Inclusion vulnerability via the 'wp_abspath' parameter. This allows unauthenticated attackers to execute arbitrary code on th...