Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Eshop MEDIUM 5.3
CVE-2023-38330

OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upl…

Fix: 6.5.3+
Fix from $1,600 2023-08-02
Eshop HIGH 8.8
CVE-2019-17062

An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professi…

Fix: 6.0.6 / 6.1.5+
Fix from $1,950 2019-11-05
Eshop CRITICAL 9.8
CVE-2019-13026

OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all…

Fix: 6.0.5 / 6.1.4+
Fix from $2,300 2019-07-30
Eshop CRITICAL 9.8
CVE-2018-20715

The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParamete…

Mitigation only
Fix from $2,300 2019-01-15
Eshop HIGH 8.1
CVE-2018-12579

An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8…

Fix: after 5.3.7
Fix from $1,950 2018-08-20
Eshop HIGH 7.5
CVE-2017-12415

OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition…

Fix: 4.9.10 / 4.10.5+
Fix from $1,950 2018-02-20
Eshop HIGH 7.5
CVE-2017-14993

OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition…

Fix: 4.9.11 / 4.10.6+
Fix from $1,950 2018-02-20
Eshop MEDIUM 5.9
CVE-2018-5763

An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able t…

Fix: 5.3.7+
Fix from $1,600 2018-02-19
Eshop HIGH 7.5
CVE-2015-6926

The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address …

Fix: after 4.4.8
Fix from $1,950 2018-01-19
Eshop MEDIUM 5.4
CVE-2014-4919

OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition …

Fix: 4.7.13 / 4.8.7+
Fix from $1,600 2018-01-19