Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Moderate

CVE-2020-8200

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
Attacker Value
Unknown

CVE-2024-11336

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce validation via the cs_menu page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-29036

Disclosure Date: March 20, 2024 (last updated January 05, 2025)
Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone. Users should upgrade to a version that incorporates commit 579241e75a5eb332ccf26e0bcdd54befa33f4783 or later to receive a patch. A possible workaround is to temporarily disable authentication by changing the usage of `createSaleorAuthClient()`.
0
Attacker Value
Unknown

CVE-2023-5914

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
  Cross-site scripting (XSS)
Attacker Value
Unknown

CVE-2023-3294

Disclosure Date: June 16, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.
Attacker Value
Unknown

CVE-2022-27503

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
Attacker Value
Unknown

CVE-2021-24607

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
Attacker Value
Unknown

CVE-2020-11883

Disclosure Date: April 17, 2020 (last updated February 21, 2025)
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.
Attacker Value
Unknown

CVE-2019-13608

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
0
Attacker Value
Unknown

CVE-2008-1341

Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0