Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
shopizer shopizer vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-4962
Shopizer 1.1.5 and previous versions allows remote malicious users to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.
Shopizer Shopizer
1 EDB exploit
4.8
CVSSv3
CVE-2021-33561
A stored cross-site scripting (XSS) vulnerability in Shopizer prior to 2.17.0 allows remote malicious users to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store a...
Shopizer Shopizer
4.8
CVSSv3
CVE-2021-33562
A reflected cross-site scripting (XSS) vulnerability in Shopizer prior to 2.17.0 allows remote malicious users to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL.
Shopizer Shopizer
4.8
CVSSv3
CVE-2022-23060
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 up to and including 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab
Shopizer Shopizer
8.8
CVSSv3
CVE-2022-23063
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.
Shopizer Shopizer
5.4
CVSSv3
CVE-2020-11006
In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.
Shopizer Shopizer
6.5
CVSSv3
CVE-2020-11007
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patc...
Shopizer Shopizer
NA
CVE-2014-5385
com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and previous versions does not restrict the number of authentication attempts, which makes it easier for remote malicious users to guess passwords via a brute force attack.
Shopizer Shopizer
4.8
CVSSv3
CVE-2022-23059
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 up to and including 2.17.0 via the “Manage Images” tab, which allows an malicious user to upload a SVG file containing malicious JavaScript code.
Shopizer Shopizer
6.5
CVSSv3
CVE-2022-23061
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.
Shopizer Shopizer
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »