Show filters
378 Total Results
Displaying 191-200 of 378
Sort by:
Attacker Value
Unknown
CVE-2022-28451
Disclosure Date: May 02, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
0
Attacker Value
Unknown
CVE-2022-28450
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
0
Attacker Value
Unknown
CVE-2022-28449
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
0
Attacker Value
Unknown
CVE-2022-28448
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
0
Attacker Value
Unknown
CVE-2022-27357
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-27346
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-26624
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.
0
Attacker Value
Unknown
CVE-2022-27436
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
0
Attacker Value
Unknown
CVE-2022-27435
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
0
Attacker Value
Unknown
CVE-2021-24940
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
0