Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

B2b2c Multi Business HIGH 8.8
CVE-2024-28559

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbat…

Fix: after 5.3.3
Fix from $1,950 2024-03-22
B2b2c Multi Business MEDIUM 5.4
CVE-2024-28560

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Addres…

Fix: after 5.3.3
Fix from $1,600 2024-03-22
B2b2c Multi Business CRITICAL 9.8
CVE-2024-25247

SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and long…

No fix yet
Fix from $2,300 2024-02-26
B2b2c Multi Business CRITICAL 9.8
CVE-2024-25248

SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id …

No fix yet
Fix from $2,300 2024-02-26
B2b2c Multi Business CRITICAL 9.8
CVE-2024-0933

A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functionality of the file \app\model…

Mitigation only
Fix from $2,300 2024-01-26
Niushop CRITICAL 9.8
CVE-2020-19672

Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, b…

No fix yet
Fix from $2,300 2020-09-30
Niushop HIGH 8.8
CVE-2019-16311

NIUSHOP V1.11 has CSRF via search_info to index.php.

No fix yet
Fix from $1,950 2019-09-14
Niushop MEDIUM 5.4
CVE-2019-16310

NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.

No fix yet
Fix from $1,600 2019-09-14
B2b2c Multi Business HIGH 8.8
CVE-2018-14570

A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to…

No fix yet
Fix from $1,950 2018-07-23