Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Moderate
CVE-2020-8200
Disclosure Date: September 18, 2020 (last updated February 22, 2025)
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
3
Attacker Value
Unknown
CVE-2024-11336
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce validation via the cs_menu page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-29036
Disclosure Date: March 20, 2024 (last updated January 05, 2025)
Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone. Users should upgrade to a version that incorporates commit 579241e75a5eb332ccf26e0bcdd54befa33f4783 or later to receive a patch. A possible workaround is to temporarily disable authentication by changing the usage of `createSaleorAuthClient()`.
0
Attacker Value
Unknown
CVE-2023-5914
Disclosure Date: January 17, 2024 (last updated January 25, 2024)
Cross-site scripting (XSS)
0
Attacker Value
Unknown
CVE-2023-3294
Disclosure Date: June 16, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.
0
Attacker Value
Unknown
CVE-2022-27503
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
0
Attacker Value
Unknown
CVE-2021-24607
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
0
Attacker Value
Unknown
CVE-2020-11883
Disclosure Date: April 17, 2020 (last updated February 21, 2025)
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.
0
Attacker Value
Unknown
CVE-2019-13608
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
0
Attacker Value
Unknown
CVE-2008-1341
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0