Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
shopizer vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2014-5385
com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and previous versions does not restrict the number of authentication attempts, which makes it easier for remote malicious users to guess passwords via a brute force attack.
Shopizer Shopizer
3.5
CVSSv2
CVE-2022-23059
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 up to and including 2.17.0 via the “Manage Images” tab, which allows an malicious user to upload a SVG file containing malicious JavaScript code.
Shopizer Shopizer
3.5
CVSSv2
CVE-2022-23060
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 up to and including 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab
Shopizer Shopizer
5.5
CVSSv2
CVE-2022-23061
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.
Shopizer Shopizer
6.5
CVSSv2
CVE-2022-23063
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.
Shopizer Shopizer
3.5
CVSSv2
CVE-2021-33562
A reflected cross-site scripting (XSS) vulnerability in Shopizer prior to 2.17.0 allows remote malicious users to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL.
Shopizer Shopizer
3.5
CVSSv2
CVE-2021-33561
A stored cross-site scripting (XSS) vulnerability in Shopizer prior to 2.17.0 allows remote malicious users to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store a...
Shopizer Shopizer
6.4
CVSSv2
CVE-2014-4962
Shopizer 1.1.5 and previous versions allows remote malicious users to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.
Shopizer Shopizer
1 EDB exploit
6.8
CVSSv2
CVE-2014-4963
Shopizer 1.1.5 and previous versions allows remote malicious users to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.
Shopizer Shopizer
1 EDB exploit
6.8
CVSSv2
CVE-2014-4964
Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and previous versions allow remote malicious users to hijack the authentication of users for requests that (1) modify customer settings or hijack the authentication of administrators for requests that ch...
Shopizer Shopizer
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27977
IMAP
local users
CVE-2024-32038
CVE-2023-49963
CVE-2023-22869
CVE-2024-31497
local
CVE-2024-2961
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »