Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cs Cart HIGH 8.6
CVE-2025-50850

An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and ra…

Mitigation only
Fix from $1,950 2025-07-31
Cs Cart MEDIUM 6.5
CVE-2025-50847

Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP re…

Mitigation only
Fix from $1,600 2025-07-31
Cs Cart MEDIUM 6.1
CVE-2025-50848

A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload o…

Mitigation only
Fix from $1,600 2025-07-31
Cs Cart Multivendor HIGH 7.2
CVE-2023-26691

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a …

No fix yet
Fix from $1,950 2024-09-25
Cs Cart Multivendor CRITICAL 9.8
CVE-2023-26686

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a…

No fix yet
Fix from $2,300 2024-09-25
Cs Cart Multivendor CRITICAL 9.8
CVE-2023-26689

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

No fix yet
Fix from $2,300 2024-09-25
Cs Cart Multivendor HIGH 8.8
CVE-2023-26687

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data paramete…

No fix yet
Fix from $1,950 2024-09-25
Cs Cart Multivendor HIGH 8.8
CVE-2023-26690

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor…

No fix yet
Fix from $1,950 2024-09-25
Cs Cart Multivendor MEDIUM 5.4
CVE-2023-26688

Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter o…

No fix yet
Fix from $1,600 2024-09-25
Cs Cart MEDIUM 6.1
CVE-2021-32202

In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page.

Mitigation only
Fix from $1,600 2021-09-14
Cs Cart MEDIUM 5.4
CVE-2017-10886

Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.1…

Mitigation only
Fix from $1,600 2017-11-17
Cs Cart MEDIUM 6.8
CVE-2015-2701

Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that chan…

No fix yet
Fix from $1,600 2015-03-25
Cs Cart HIGH 7.5
CVE-2009-4891

SQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id paramet…

No fix yet
Fix from $1,950 2010-06-11
Cs Cart HIGH 7.5
CVE-2007-0230

PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the instal…

Mitigation only
Fix from $1,950 2007-01-13
Cs Cart HIGH 7.5
CVE-2005-4429

SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order paramet…

No fix yet
Fix from $1,950 2005-12-21