Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Oscommerce MEDIUM 5.4
CVE-2023-43716

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MAX…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43712

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "acc…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43713

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43707

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "Cat…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43708

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43709

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43710

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43711

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "adm…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43702

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tra…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43703

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "pro…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43704

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tit…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43705

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tra…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43706

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ema…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 6.1
CVE-2022-35212

osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().

Fix: 2.3.4.1+
Fix from $1,600 2022-08-18
Oscommerce CRITICAL 9.8
CVE-2020-23360

oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /c…

No fix yet
Fix from $2,300 2021-01-27
Oscommerce CRITICAL 9.8
CVE-2020-27976EPSS 7%

osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the applicat…

Fix: 1.0.5.4+
Fix from $2,300 2020-10-28
Oscommerce HIGH 8.8
CVE-2020-27975

osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.

Fix: 1.0.5.4+
Fix from $1,950 2020-10-28
Ce Phoenix MEDIUM 6.1
CVE-2020-12058

Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious …

Patch available
Fix from $1,600 2020-09-03
Oscommerce HIGH 7.2
CVE-2018-18573

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.…

Mitigation only
Fix from $1,950 2019-08-22
Oscommerce HIGH 7.2
CVE-2018-18572

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP…

Mitigation only
Fix from $1,950 2019-08-22
Online Merchant MEDIUM 6.5
CVE-2014-10033

SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remot…

Fix: after 2.3.3.4
Fix from $1,600 2015-01-13
Oscommerce MEDIUM 5.8
CVE-2012-5792

The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…

No fix yet
Fix from $1,600 2012-11-04
Oscommerce MEDIUM 5.8
CVE-2012-5796

The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,600 2012-11-04
Oscommerce MEDIUM 5.8
CVE-2012-5798

The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or su…

No fix yet
Fix from $1,600 2012-11-04
Online Merchant MEDIUM 5.0
CVE-2012-2991

The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payme…

Fix: after 2.3.3
Fix from $1,600 2012-09-19
Oscommerce HIGH 7.5
CVE-2011-4543

Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .. (dot do…

No fix yet
Fix from $1,950 2011-12-05
Oscommerce MEDIUM 5.0
CVE-2011-3767

osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

Mitigation only
Fix from $1,600 2011-09-24
Finnish Bank Payment HIGH 10.0
CVE-2009-2038

Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charges.

Patch available
Fix from $1,950 2009-06-12
Luottokunta HIGH 10.0
CVE-2009-2039

Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.

Patch available
Fix from $1,950 2009-06-12
Oscommerce MEDIUM 6.0
CVE-2009-0408

Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.

Mitigation only
Fix from $1,600 2009-02-03