Show filters
378 Total Results
Displaying 221-230 of 378
Sort by:
Attacker Value
Unknown

CVE-2020-35627

Disclosure Date: December 28, 2020 (last updated February 22, 2025)
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift Card Template", the function of uploading a custom image is used, changing the name of the image extension to PHP and executing PHP code on the server.
Attacker Value
Unknown

CVE-2020-29156

Disclosure Date: December 27, 2020 (last updated February 22, 2025)
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
Attacker Value
Unknown

CVE-2020-29070

Disclosure Date: November 25, 2020 (last updated February 22, 2025)
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
Attacker Value
Unknown

CVE-2020-26223

Disclosure Date: November 13, 2020 (last updated February 22, 2025)
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.
Attacker Value
Unknown

CVE-2020-21266

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.
Attacker Value
Unknown

CVE-2020-27975

Disclosure Date: October 28, 2020 (last updated February 22, 2025)
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
Attacker Value
Unknown

CVE-2020-27976

Disclosure Date: October 28, 2020 (last updated February 22, 2025)
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.
Attacker Value
Unknown

CVE-2020-12058

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.
Attacker Value
Unknown

CVE-2020-25093

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
Attacker Value
Unknown

CVE-2020-25086

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.