Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2024-5762EPSS 72% Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… Zen Cart Mitigation only Fix from $1,9502024-08-21 MEDIUM 6.1 CVE-2020-6578 Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/template… Zen Cart No fix yet Fix from $1,6002021-03-19 HIGH 7.2 CVE-2021-3291EPSS 17% Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting… Zen Cart No fix yet Fix from $1,9502021-01-26 HIGH 8.8 CVE-2017-11675 The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows re… Zen Cart Mitigation only Fix from $1,9502017-07-27 MEDIUM 6.1 CVE-2017-10667 In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS. Zen Cart Mitigation only Fix from $1,6002017-06-29 MEDIUM 6.1 CVE-2017-8833 Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link … Zen Cart No fix yet Fix from $1,6002017-05-08 MEDIUM 5.8 CVE-2011-4403 Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators f… Zen Cart No fix yet Fix from $1,6002015-04-24 HIGH 7.5 CVE-2009-4323 The installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) … Zen Cart Mitigation only Fix from $1,9502009-12-14 MEDIUM 5.0 CVE-2009-4321 extras/curltest.php in Zen Cart 1.3.8 and 1.3.8a, and possibly other versions, allows remote attackers to read arbitrary files via a file:// URI. NO… Zen Cart No fix yet Fix from $1,6002009-12-14 MEDIUM 5.0 CVE-2009-4322 extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation p… Zen Cart No fix yet Fix from $1,6002009-12-14 MEDIUM 6.8 CVE-2008-6985 Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, all… Zen Cart No fix yet Fix from $1,6002009-08-19 MEDIUM 6.8 CVE-2008-6986 SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when mag… Zen Cart No fix yet Fix from $1,6002009-08-19 HIGH 7.5 CVE-2008-6615 SQL injection vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to execute arbitrary SQL commands via the keyword para… Zen Cart No fix yet Fix from $1,9502009-04-06