Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2023-43716
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "MAX…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43712
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "acc…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43713
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability,
which allows attackers to inject JS via the "title" parameter, in…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43707
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "Cat…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43708
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "con…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43709
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "con…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43710
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "con…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43711
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "adm…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43702
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "tra…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43703
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "pro…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43704
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "tit…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43705
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "tra…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43706
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "ema…
Oscommerce
No fix yet
MEDIUM 6.1
CVE-2022-35212
osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().
Oscommerce
2.3.4.1+
CRITICAL 9.8
CVE-2020-23360
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /c…
Oscommerce
No fix yet
CRITICAL 9.8
CVE-2020-27976EPSS 7%
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the applicat…
Oscommerce
1.0.5.4+
HIGH 8.8
CVE-2020-27975
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
Oscommerce
1.0.5.4+
MEDIUM 6.1
CVE-2020-12058
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious …
Ce Phoenix
Patch available
HIGH 7.2
CVE-2018-18573
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.…
Oscommerce
Mitigation only
HIGH 7.2
CVE-2018-18572
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP…
Oscommerce
Mitigation only
MEDIUM 6.5
CVE-2014-10033
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remot…
Online Merchant
after 2.3.3.4
MEDIUM 5.8
CVE-2012-5792
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…
Oscommerce
No fix yet
MEDIUM 5.8
CVE-2012-5796
The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…
Oscommerce
No fix yet
MEDIUM 5.8
CVE-2012-5798
The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or su…
Oscommerce
No fix yet
MEDIUM 5.0
CVE-2012-2991
The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payme…
Online Merchant
after 2.3.3
HIGH 7.5
CVE-2011-4543
Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .. (dot do…
Oscommerce
No fix yet
MEDIUM 5.0
CVE-2011-3767
osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …
Oscommerce
Mitigation only
HIGH 10.0
CVE-2009-2038
Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charges.
Finnish Bank Payment
Patch available
HIGH 10.0
CVE-2009-2039
Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.
Luottokunta
Patch available
MEDIUM 6.0
CVE-2009-0408
Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.
Oscommerce
Mitigation only