Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2025-50850 An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and ra… Cs Cart Mitigation only Fix from $1,9502025-07-31 MEDIUM 6.5 CVE-2025-50847 Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP re… Cs Cart Mitigation only Fix from $1,6002025-07-31 MEDIUM 6.1 CVE-2025-50848 A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload o… Cs Cart Mitigation only Fix from $1,6002025-07-31 HIGH 7.2 CVE-2023-26691 Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a … Cs Cart Multivendor No fix yet Fix from $1,9502024-09-25 CRITICAL 9.8 CVE-2023-26686 File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a… Cs Cart Multivendor No fix yet Fix from $2,3002024-09-25 CRITICAL 9.8 CVE-2023-26689 An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request. Cs Cart Multivendor No fix yet Fix from $2,3002024-09-25 HIGH 8.8 CVE-2023-26687 Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data paramete… Cs Cart Multivendor No fix yet Fix from $1,9502024-09-25 HIGH 8.8 CVE-2023-26690 File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor… Cs Cart Multivendor No fix yet Fix from $1,9502024-09-25 MEDIUM 5.4 CVE-2023-26688 Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter o… Cs Cart Multivendor No fix yet Fix from $1,6002024-09-25 MEDIUM 6.1 CVE-2021-32202 In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page. Cs Cart Mitigation only Fix from $1,6002021-09-14 HIGH 7.2 CVE-2017-15673 The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a … Cs Cart after 4.6.2 Fix from $1,9502017-11-28 MEDIUM 5.4 CVE-2017-10886 Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.1… Cs Cart Mitigation only Fix from $1,6002017-11-17 HIGH 8.8 CVE-2017-2138 Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese E… Cs Cart after 4.3.10 Fix from $1,9502017-08-02 HIGH 8.8 CVE-2016-4862 Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to exec… Cs Cart after 4.3.9 Fix from $1,9502017-04-20 MEDIUM 6.8 CVE-2015-2701 Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that chan… Cs Cart No fix yet Fix from $1,6002015-03-25 MEDIUM 5.0 CVE-2013-0118 CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the m… Cs Cart after 3.0.5 Fix from $1,6002013-02-24 HIGH 7.5 CVE-2009-4891 SQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id paramet… Cs Cart No fix yet Fix from $1,9502010-06-11 MEDIUM 6.5 CVE-2009-2579 SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute… Cs Cart after 2.0.5 Fix from $1,6002009-08-05 HIGH 7.5 CVE-2008-6394 SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookie… Cs Cart after 1.3.5 Fix from $1,9502009-03-04 HIGH 7.5 CVE-2007-0230 PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the instal… Cs Cart Mitigation only Fix from $1,9502007-01-13 MEDIUM 5.1 CVE-2006-2863EPSS 10% PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in… Cs Cart after 1.3.3 Fix from $1,6002006-06-06 HIGH 7.5 CVE-2005-4429 SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order paramet… Cs Cart No fix yet Fix from $1,9502005-12-21