Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
virtuemart virtuemart vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2016-10114
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension prior to 2.6.1 for Joomla! allows remote malicious users to execute arbitrary SQL commands via vectors involving categorysearch and smartSearch.
Awebsupport Aweb Cart Watching System For Virtuemart 2.6.0
7.2
CVSSv3
CVE-2016-10379
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.
Virtuemart Virtuemart 3.0.14
5.4
CVSSv3
CVE-2018-7465
An XSS issue exists in VirtueMart prior to 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser will execute everything aft...
Virtuemart Virtuemart
1 EDB exploit
5.4
CVSSv3
CVE-2015-3619
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component prior to 3.0.8 for Joomla! allows remote malicious users to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and compa...
Virtuemart Virtuemart
NA
CVE-2009-4430
SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote malicious users to execute arbitrary SQL commands via the product_id parameter in a shop.product_details shop.flypage action.
Virtuemart Virtuemart 1.0
1 EDB exploit
NA
CVE-2008-7205
Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and previous versions allows remote malicious users to read arbitrary files via vectors related to a template file.
Virtuemart Virtuemart 1.0.0
Virtuemart Virtuemart 1.0.7
Virtuemart Virtuemart 1.0.10
Virtuemart Virtuemart 1.0.9
Virtuemart Virtuemart 1.0.12
Virtuemart Virtuemart 1.1
Virtuemart Virtuemart 1.0.11
Virtuemart Virtuemart 1.0.8
Virtuemart Virtuemart
NA
CVE-2008-7204
Cross-site request forgery (CSRF) vulnerability in VirtueMart 1.0.13a and previous versions allows remote malicious users to hijack the authentication of administrators via unspecified vectors.
Virtuemart Virtuemart 1.0.12
Virtuemart Virtuemart 1.1
Virtuemart Virtuemart 1.0.0
Virtuemart Virtuemart 1.0.7
Virtuemart Virtuemart 1.0.11
Virtuemart Virtuemart 1.0.8
Virtuemart Virtuemart
Virtuemart Virtuemart 1.0.10
Virtuemart Virtuemart 1.0.9
NA
CVE-2008-6483
PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote malicious users to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Virtuemart-solutions Com Googlebase 1.1
1 EDB exploit
NA
CVE-2007-5563
Unspecified vulnerability in VirtueMart prior to 1.0.13 allows remote malicious users to execute arbitrary PHP code via unspecified vectors.
Virtuemart Virtuemart
NA
CVE-2007-3247
SQL injection vulnerability in VirtueMart prior to 1.0.11 allows remote malicious users to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php.
Virtuemart Virtuemart
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »