Show filters
87 Total Results
Displaying 21-30 of 87
Sort by:
Attacker Value
Unknown
CVE-2023-28843
Disclosure Date: March 31, 2023 (last updated February 24, 2025)
PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain privileges, modify data, and potentially affect system availability. The cause of this issue is that SQL queries were being constructed with user input which had not been properly filtered. Only deployments on PrestaShop 1.6 are affected. Users are advised to upgrade to module version 3.16.4. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-27638
Disclosure Date: March 22, 2023 (last updated February 24, 2025)
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.
0
Attacker Value
Unknown
CVE-2023-27637
Disclosure Date: March 22, 2023 (last updated February 24, 2025)
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.
0
Attacker Value
Unknown
CVE-2022-46965
Disclosure Date: February 02, 2023 (last updated February 24, 2025)
PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
0
Attacker Value
Unknown
CVE-2023-23010
Disclosure Date: January 20, 2023 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.
0
Attacker Value
Unknown
CVE-2022-42699
Disclosure Date: December 06, 2022 (last updated February 24, 2025)
Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
0
Attacker Value
Unknown
CVE-2022-45833
Disclosure Date: December 06, 2022 (last updated February 24, 2025)
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
0
Attacker Value
Unknown
CVE-2022-45829
Disclosure Date: December 06, 2022 (last updated February 24, 2025)
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-45990
Disclosure Date: December 05, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
0
Attacker Value
Unknown
CVE-2022-3334
Disclosure Date: October 31, 2022 (last updated February 24, 2025)
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
0