Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zen Cart HIGH 8.1
CVE-2024-5762EPSS 72%

Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2024-08-21
Zen Cart MEDIUM 6.1
CVE-2020-6578

Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/template…

No fix yet
Fix from $1,600 2021-03-19
Zen Cart HIGH 7.2
CVE-2021-3291EPSS 17%

Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting…

No fix yet
Fix from $1,950 2021-01-26
Zen Cart CRITICAL 9.8
CVE-2015-8352EPSS 16%

Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ac…

Patch available
Fix from $2,300 2017-08-24
Zen Cart HIGH 8.8
CVE-2017-11675

The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows re…

Mitigation only
Fix from $1,950 2017-07-27
Zen Cart MEDIUM 6.1
CVE-2017-10667

In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.

Mitigation only
Fix from $1,600 2017-06-29
Zen Cart MEDIUM 6.1
CVE-2017-8833

Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link …

No fix yet
Fix from $1,600 2017-05-08
Zen Cart MEDIUM 5.8
CVE-2011-4403

Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators f…

No fix yet
Fix from $1,600 2015-04-24
Zen Cart HIGH 7.5
CVE-2009-4323

The installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) …

Mitigation only
Fix from $1,950 2009-12-14
Zen Cart MEDIUM 5.0
CVE-2009-4321

extras/curltest.php in Zen Cart 1.3.8 and 1.3.8a, and possibly other versions, allows remote attackers to read arbitrary files via a file:// URI. NO…

No fix yet
Fix from $1,600 2009-12-14
Zen Cart MEDIUM 5.0
CVE-2009-4322

extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation p…

No fix yet
Fix from $1,600 2009-12-14
Zen Cart MEDIUM 6.8
CVE-2008-6985

Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, all…

No fix yet
Fix from $1,600 2009-08-19
Zen Cart MEDIUM 6.8
CVE-2008-6986

SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when mag…

No fix yet
Fix from $1,600 2009-08-19
Zen Cart MEDIUM 6.8
CVE-2009-2255EPSS 31%

Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to exe…

Fix: after 1.3.8a
Fix from $1,600 2009-06-30
Zen Cart HIGH 7.5
CVE-2009-2254EPSS 11%

Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute a…

Fix: after 1.3.8a
Fix from $1,950 2009-06-30
Zen Cart HIGH 7.5
CVE-2008-6615

SQL injection vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to execute arbitrary SQL commands via the keyword para…

No fix yet
Fix from $1,950 2009-04-06
Zen Cart HIGH 10.0
CVE-2006-0697EPSS 5%

Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, p…

Fix: after 1.2.6d
Fix from $1,950 2006-02-15
Zen Cart MEDIUM 5.1
CVE-2005-3996

SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands …

Fix: after 1.2.6d
Fix from $1,600 2005-12-05