Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
virtuemart virtuemart vulnerabilities and exploits
(subscribe to this query)
605
VMScore
CVE-2008-7204
Cross-site request forgery (CSRF) vulnerability in VirtueMart 1.0.13a and previous versions allows remote malicious users to hijack the authentication of administrators via unspecified vectors.
Virtuemart Virtuemart 1.0.12
Virtuemart Virtuemart 1.1
Virtuemart Virtuemart 1.0.0
Virtuemart Virtuemart 1.0.7
Virtuemart Virtuemart 1.0.11
Virtuemart Virtuemart 1.0.8
Virtuemart Virtuemart
Virtuemart Virtuemart 1.0.10
Virtuemart Virtuemart 1.0.9
383
VMScore
CVE-2008-7205
Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and previous versions allows remote malicious users to read arbitrary files via vectors related to a template file.
Virtuemart Virtuemart 1.0.0
Virtuemart Virtuemart 1.0.7
Virtuemart Virtuemart 1.0.10
Virtuemart Virtuemart 1.0.9
Virtuemart Virtuemart 1.0.12
Virtuemart Virtuemart 1.1
Virtuemart Virtuemart 1.0.11
Virtuemart Virtuemart 1.0.8
Virtuemart Virtuemart
383
VMScore
CVE-2007-1361
Cross-site scripting (XSS) vulnerability in virtuemart_parser.php in VirtueMart prior to 20070213 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue is probably different than CVE-2007-0376.
Virtuemart Virtuemart
668
VMScore
CVE-2007-5563
Unspecified vulnerability in VirtueMart prior to 1.0.13 allows remote malicious users to execute arbitrary PHP code via unspecified vectors.
Virtuemart Virtuemart
312
VMScore
CVE-2015-3619
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component prior to 3.0.8 for Joomla! allows remote malicious users to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and compa...
Virtuemart Virtuemart
355
VMScore
CVE-2018-7465
An XSS issue exists in VirtueMart prior to 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser will execute everything aft...
Virtuemart Virtuemart
1 EDB exploit
890
VMScore
CVE-2005-4829
VirtueMart prior to 1.0.1 does not properly handle errors when a user is forbidden to read a requested page, which has unknown impact and remote attack vectors.
Virtuemart Virtuemart
605
VMScore
CVE-2007-3247
SQL injection vulnerability in VirtueMart prior to 1.0.11 allows remote malicious users to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php.
Virtuemart Virtuemart
605
VMScore
CVE-2007-1096
Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart prior to 20070116 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue might overlap CVE-2007-0376.
Virtuemart Virtuemart
668
VMScore
CVE-2006-6945
SQL injection vulnerability in Virtuemart 1.0.7 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors, probably related to (1) Itemid, (2) product_id, and category_id parameters as handled in virtuemart_parser.php.
Virtuemart Virtuemart 1.0.7
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »