Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
shopizer vulnerabilities and exploits
(subscribe to this query)
4.8
CVSSv3
CVE-2022-23060
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 up to and including 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab
Shopizer Shopizer
NA
CVE-2014-4962
Shopizer 1.1.5 and previous versions allows remote malicious users to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.
Shopizer Shopizer
1 EDB exploit
NA
CVE-2014-4964
Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and previous versions allow remote malicious users to hijack the authentication of users for requests that (1) modify customer settings or hijack the authentication of administrators for requests that ch...
Shopizer Shopizer
1 EDB exploit
NA
CVE-2014-4965
Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) customername parameter to central/orders/searchcriteria.action; (2) productname, (3) availability, or (4) st...
Shopizer Shopizer
1 EDB exploit
NA
CVE-2014-4963
Shopizer 1.1.5 and previous versions allows remote malicious users to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.
Shopizer Shopizer
1 EDB exploit
NA
CVE-2014-5385
com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and previous versions does not restrict the number of authentication attempts, which makes it easier for remote malicious users to guess passwords via a brute force attack.
Shopizer Shopizer
4.8
CVSSv3
CVE-2021-33561
A stored cross-site scripting (XSS) vulnerability in Shopizer prior to 2.17.0 allows remote malicious users to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store a...
Shopizer Shopizer
4.8
CVSSv3
CVE-2021-33562
A reflected cross-site scripting (XSS) vulnerability in Shopizer prior to 2.17.0 allows remote malicious users to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL.
Shopizer Shopizer
5.4
CVSSv3
CVE-2020-11006
In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.
Shopizer Shopizer
6.5
CVSSv3
CVE-2022-23061
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.
Shopizer Shopizer
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »