Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-5108
A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/cont…
Shopxo
Mitigation only
MEDIUM 6.5
CVE-2025-28094
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
Shopxo
No fix yet
MEDIUM 6.3
CVE-2025-28092
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
Shopxo
No fix yet
MEDIUM 6.3
CVE-2025-28093
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
Shopxo
No fix yet
CRITICAL 9.8
CVE-2025-26325
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
Shopxo
No fix yet
MEDIUM 6.1
CVE-2024-44682
ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.
Shopxo
Mitigation only
HIGH 8.8
CVE-2024-6524
A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …
Shopxo
after 6.1.0
HIGH 7.2
CVE-2021-41938
An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.
Shopxo
No fix yet
CRITICAL 9.8
CVE-2022-28056
ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.
Shopxo
No fix yet
HIGH 7.8
CVE-2020-26007
An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a craft…
Shopxo
No fix yet
HIGH 7.8
CVE-2020-26008
The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allo…
Shopxo
No fix yet
CRITICAL 9.8
CVE-2020-19778
Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_i…
Shopxo
No fix yet
CRITICAL 9.8
CVE-2021-27817
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which…
Shopxo
Mitigation only
HIGH 8.8
CVE-2020-24220
ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the serve…
Shopxo
Mitigation only
CRITICAL 9.8
CVE-2019-5886
An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, wh…
Shopxo
No fix yet
HIGH 7.5
CVE-2019-5887
An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not checked, resulting in input m…
Shopxo
No fix yet