Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
shopizer vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2022-23059
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 up to and including 2.17.0 via the “Manage Images” tab, which allows an malicious user to upload a SVG file containing malicious JavaScript code.
Shopizer Shopizer
3.5
CVSSv2
CVE-2022-23060
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 up to and including 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab
Shopizer Shopizer
6.8
CVSSv2
CVE-2014-4964
Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and previous versions allow remote malicious users to hijack the authentication of users for requests that (1) modify customer settings or hijack the authentication of administrators for requests that ch...
Shopizer Shopizer
1 EDB exploit
3.5
CVSSv2
CVE-2020-11006
In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.
Shopizer Shopizer
4
CVSSv2
CVE-2020-11007
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patc...
Shopizer Shopizer
5
CVSSv2
CVE-2014-5385
com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and previous versions does not restrict the number of authentication attempts, which makes it easier for remote malicious users to guess passwords via a brute force attack.
Shopizer Shopizer
6.4
CVSSv2
CVE-2014-4962
Shopizer 1.1.5 and previous versions allows remote malicious users to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.
Shopizer Shopizer
1 EDB exploit
6.8
CVSSv2
CVE-2014-4963
Shopizer 1.1.5 and previous versions allows remote malicious users to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.
Shopizer Shopizer
1 EDB exploit
4.3
CVSSv2
CVE-2014-4965
Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) customername parameter to central/orders/searchcriteria.action; (2) productname, (3) availability, or (4) st...
Shopizer Shopizer
1 EDB exploit
3.5
CVSSv2
CVE-2021-33561
A stored cross-site scripting (XSS) vulnerability in Shopizer prior to 2.17.0 allows remote malicious users to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store a...
Shopizer Shopizer
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »