Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zen vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-5119
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart 1.3.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) admin_name or (2) admin_pass parameter in (a) admin/login.php, or the (3) admin_email parameter in (b) admin/password_forgotten.ph...
Zen Cart Zen Cart 1.3.5
8.8
CVSSv3
CVE-2017-11675
The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that code into an invalid array index of the admin_name array par...
Zen-cart Zen Cart 1.5.5e
NA
CVE-2006-3757
index.php in Zen Cart 1.3.0.2 allows remote malicious users to obtain sensitive information via empty (1) _GET[], (2) _SESSION[], (3) _POST[], (4) _COOKIE[], or (5) _SESSION[] array parameters, which reveals the installation path in an error message. NOTE: this issue might be res...
Zen Cart Zen Cart 1.3.0.2
6.1
CVSSv3
CVE-2020-6578
Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.
Zen-cart Zen Cart 1.5.6d
7.2
CVSSv3
CVE-2021-3291
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
Zen-cart Zen Cart 1.5.7b
2 Github repositories
NA
CVE-2011-4547
Multiple cross-site scripting (XSS) vulnerabilities in includes/templates/template_default/common/tpl_header_test_info.php in Zen Cart 1.3.9h, when debugging is enabled, might allow remote malicious users to inject arbitrary web script or HTML via the (1) main_page parameter or (...
Zen-cart Zen Cart 1.3.9h
NA
CVE-2011-4403
Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote malicious users to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setfl...
Zen-cart Zen Cart 1.3.9h
1 EDB exploit
6.1
CVSSv3
CVE-2017-8833
Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github."
Zen-cart Zen Cart 1.6.0
NA
CVE-2006-6868
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart prior to 1.3.7 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Zen Cart Web Shopping Cart 1.2.6d
Zen Cart Web Shopping Cart 1.2.7
Zen Cart Web Shopping Cart 1.3.5
Zen Cart Web Shopping Cart 1.3
Zen Cart Web Shopping Cart 1.3.2
Zen Cart Web Shopping Cart 1.1.2d
NA
CVE-2012-5808
The LinkPoint module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid cert...
Firstdata Linkpoint -
Zen-cart Zen Cart -
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »