Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Shopxo CRITICAL 9.8
CVE-2025-5108

A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/cont…

Mitigation only
Fix from $2,300 2025-05-23
Shopxo MEDIUM 6.5
CVE-2025-28094

shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

No fix yet
Fix from $1,600 2025-03-28
Shopxo MEDIUM 6.3
CVE-2025-28092

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.

No fix yet
Fix from $1,600 2025-03-28
Shopxo MEDIUM 6.3
CVE-2025-28093

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.

No fix yet
Fix from $1,600 2025-03-28
Shopxo CRITICAL 9.8
CVE-2025-26325

ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.

No fix yet
Fix from $2,300 2025-02-27
Shopxo MEDIUM 6.1
CVE-2024-44682

ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.

Mitigation only
Fix from $1,600 2024-08-30
Shopxo HIGH 7.2
CVE-2021-41938

An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.

No fix yet
Fix from $1,950 2022-05-19
Shopxo CRITICAL 9.8
CVE-2022-28056

ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.

No fix yet
Fix from $2,300 2022-05-02
Shopxo HIGH 7.8
CVE-2020-26007

An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a craft…

No fix yet
Fix from $1,950 2022-03-20
Shopxo HIGH 7.8
CVE-2020-26008

The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allo…

No fix yet
Fix from $1,950 2022-03-20
Shopxo CRITICAL 9.8
CVE-2020-19778

Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_i…

No fix yet
Fix from $2,300 2021-04-14
Shopxo CRITICAL 9.8
CVE-2021-27817

A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which…

Mitigation only
Fix from $2,300 2021-03-15
Shopxo HIGH 8.8
CVE-2020-24220

ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the serve…

Mitigation only
Fix from $1,950 2020-08-17
Shopxo CRITICAL 9.8
CVE-2019-5886

An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, wh…

No fix yet
Fix from $2,300 2019-01-10
Shopxo HIGH 7.5
CVE-2019-5887

An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not checked, resulting in input m…

No fix yet
Fix from $1,950 2019-01-10