Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-43716 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MAX… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43712 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "acc… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43713 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43707 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "Cat… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43708 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43709 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43710 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43711 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "adm… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43702 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tra… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43703 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "pro… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43704 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tit… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43705 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tra… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 5.4 CVE-2023-43706 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ema… Oscommerce No fix yet Fix from $1,6002023-09-30 MEDIUM 6.1 CVE-2022-35212 osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error(). Oscommerce 2.3.4.1+ Fix from $1,6002022-08-18 CRITICAL 9.8 CVE-2020-23360 oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /c… Oscommerce No fix yet Fix from $2,3002021-01-27 CRITICAL 9.8 CVE-2020-27976EPSS 7% osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the applicat… Oscommerce 1.0.5.4+ Fix from $2,3002020-10-28 HIGH 8.8 CVE-2020-27975 osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF. Oscommerce 1.0.5.4+ Fix from $1,9502020-10-28 MEDIUM 6.1 CVE-2020-12058 Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious … Ce Phoenix Patch available Fix from $1,6002020-09-03 HIGH 7.2 CVE-2018-18573 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.… Oscommerce Mitigation only Fix from $1,9502019-08-22 HIGH 7.2 CVE-2018-18572 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP… Oscommerce Mitigation only Fix from $1,9502019-08-22 MEDIUM 6.5 CVE-2014-10033 SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remot… Online Merchant after 2.3.3.4 Fix from $1,6002015-01-13 MEDIUM 5.8 CVE-2012-5792 The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA… Oscommerce No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5796 The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam… Oscommerce No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5798 The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or su… Oscommerce No fix yet Fix from $1,6002012-11-04 MEDIUM 5.0 CVE-2012-2991 The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payme… Online Merchant after 2.3.3 Fix from $1,6002012-09-19 HIGH 7.5 CVE-2011-4543 Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .. (dot do… Oscommerce No fix yet Fix from $1,9502011-12-05 MEDIUM 5.0 CVE-2011-3767 osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in … Oscommerce Mitigation only Fix from $1,6002011-09-24 HIGH 10.0 CVE-2009-2038 Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charges. Finnish Bank Payment Patch available Fix from $1,9502009-06-12 HIGH 10.0 CVE-2009-2039 Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders. Luottokunta Patch available Fix from $1,9502009-06-12 MEDIUM 6.0 CVE-2009-0408 Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators. Oscommerce Mitigation only Fix from $1,6002009-02-03