Show filters
378 Total Results
Displaying 221-230 of 378
Sort by:
Attacker Value
Unknown
CVE-2020-35627
Disclosure Date: December 28, 2020 (last updated February 22, 2025)
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift Card Template", the function of uploading a custom image is used, changing the name of the image extension to PHP and executing PHP code on the server.
0
Attacker Value
Unknown
CVE-2020-29156
Disclosure Date: December 27, 2020 (last updated February 22, 2025)
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
0
Attacker Value
Unknown
CVE-2020-29070
Disclosure Date: November 25, 2020 (last updated February 22, 2025)
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
0
Attacker Value
Unknown
CVE-2020-26223
Disclosure Date: November 13, 2020 (last updated February 22, 2025)
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.
0
Attacker Value
Unknown
CVE-2020-21266
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.
0
Attacker Value
Unknown
CVE-2020-27975
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
0
Attacker Value
Unknown
CVE-2020-27976
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.
0
Attacker Value
Unknown
CVE-2020-12058
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.
0
Attacker Value
Unknown
CVE-2020-25093
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
0
Attacker Value
Unknown
CVE-2020-25086
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
0