Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-5108 A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/cont… Shopxo Mitigation only Fix from $2,3002025-05-23 MEDIUM 6.5 CVE-2025-28094 shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places. Shopxo No fix yet Fix from $1,6002025-03-28 MEDIUM 6.3 CVE-2025-28092 ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function. Shopxo No fix yet Fix from $1,6002025-03-28 MEDIUM 6.3 CVE-2025-28093 ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings. Shopxo No fix yet Fix from $1,6002025-03-28 CRITICAL 9.8 CVE-2025-26325 ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php. Shopxo No fix yet Fix from $2,3002025-02-27 MEDIUM 6.1 CVE-2024-44682 ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters. Shopxo Mitigation only Fix from $1,6002024-08-30 HIGH 7.2 CVE-2021-41938 An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations. Shopxo No fix yet Fix from $1,9502022-05-19 CRITICAL 9.8 CVE-2022-28056 ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php. Shopxo No fix yet Fix from $2,3002022-05-02 HIGH 7.8 CVE-2020-26007 An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a craft… Shopxo No fix yet Fix from $1,9502022-03-20 HIGH 7.8 CVE-2020-26008 The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allo… Shopxo No fix yet Fix from $1,9502022-03-20 CRITICAL 9.8 CVE-2020-19778 Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_i… Shopxo No fix yet Fix from $2,3002021-04-14 CRITICAL 9.8 CVE-2021-27817 A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which… Shopxo Mitigation only Fix from $2,3002021-03-15 HIGH 8.8 CVE-2020-24220 ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the serve… Shopxo Mitigation only Fix from $1,9502020-08-17 CRITICAL 9.8 CVE-2019-5886 An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, wh… Shopxo No fix yet Fix from $2,3002019-01-10 HIGH 7.5 CVE-2019-5887 An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not checked, resulting in input m… Shopxo No fix yet Fix from $1,9502019-01-10