Show filters
91 Total Results
Displaying 1-10 of 91
Sort by:
Attacker Value
Moderate

CVE-2020-8200

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
Attacker Value
High

CVE-2020-1170

Disclosure Date: June 09, 2020 (last updated February 21, 2025)
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.
Attacker Value
Unknown

CVE-2024-13686

Disclosure Date: March 04, 2025 (last updated March 04, 2025)
The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the themes settings.
Attacker Value
Unknown

CVE-2025-23524

Disclosure Date: March 03, 2025 (last updated March 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ClickBank Storefront allows Reflected XSS. This issue affects ClickBank Storefront: from n/a through 1.7.
0
Attacker Value
Unknown

CVE-2024-11336

Disclosure Date: December 06, 2024 (last updated February 27, 2025)
The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce validation via the cs_menu page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-29036

Disclosure Date: March 20, 2024 (last updated February 26, 2025)
Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone. Users should upgrade to a version that incorporates commit 579241e75a5eb332ccf26e0bcdd54befa33f4783 or later to receive a patch. A possible workaround is to temporarily disable authentication by changing the usage of `createSaleorAuthClient()`.
0
Attacker Value
Unknown

CVE-2023-5914

Disclosure Date: January 17, 2024 (last updated February 26, 2025)
  Cross-site scripting (XSS)
Attacker Value
Unknown

CVE-2023-3294

Disclosure Date: June 16, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.
Attacker Value
Unknown

CVE-2022-27503

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
Attacker Value
Unknown

CVE-2021-24607

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.