Записи shopizer
14 опубликованных записей вендора shopizer.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 35,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-346 Origin Validation Error1
- CWE-189 Numeric Errors1
- CWE-613 Insufficient Session Expiration1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2022-23063Эксплойта нет | Shopizer - Insufficient Session Expirationshopizer · shopizer · CWE-613 | Высокая8,8 | — | 1,2 % | 3 мая 2022 г. |
32Наблюдать | CVE-2025-51605Эксплойта нет | An issue was discovered in Shopizer 3.2.7.shopizer · shopizer · CWE-346 | Высокая8,1 | — | 0,2 % | 22 авг. 2025 г. |
28Наблюдать | CVE-2014-4963Proof of concept | Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter tshopizer · shopizer | Средняя6,8 | — | 3,7 % | 15 июл. 2014 г. |
28Наблюдать | CVE-2014-4964Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authenticationshopizer · shopizer · CWE-352 | Средняя6,8 | — | 2,3 % | 15 июл. 2014 г. |
26Наблюдать | CVE-2014-4962Proof of concept | Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantshopizer · shopizer · CWE-189 | Средняя6,4 | — | 4,7 % | 15 июл. 2014 г. |
26Наблюдать | CVE-2022-23061Эксплойта нет | Shopizer - IDOR delete superadminshopizer · shopizer · CWE-639 | Средняя6,5 | — | 1,1 % | 1 мая 2022 г. |
26Наблюдать | CVE-2020-11007Эксплойта нет | Negative charge in shopping cart possible in Shopizershopizer · shopizer · CWE-20 | Средняя6,5 | — | 0,9 % | 16 апр. 2020 г. |
21Наблюдать | CVE-2020-11006Эксплойта нет | Potential remote code execution in Shopizershopizer · shopizer · CWE-79 | Средняя5,4 | — | 0,6 % | 8 мая 2020 г. |
20Наблюдать | CVE-2021-33562Proof of concept | A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTMshopizer · shopizer · CWE-79 | Средняя4,8 | — | 2,9 % | 24 мая 2021 г. |
20Наблюдать | CVE-2021-33561Proof of concept | A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML vshopizer · shopizer · CWE-79 | Средняя4,8 | — | 2,9 % | 24 мая 2021 г. |
20Наблюдать | CVE-2014-5385Эксплойта нет | com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, wshopizer · shopizer · CWE-287 | Средняя5,0 | — | 1,1 % | 21 авг. 2014 г. |
19Наблюдать | CVE-2022-23059Эксплойта нет | Shopizer - Stored XSS in Manage Imagesshopizer · shopizer · CWE-79 | Средняя4,8 | — | 0,6 % | 29 мар. 2022 г. |
19Наблюдать | CVE-2022-23060Эксплойта нет | Shopizer - Stored XSS in Manage Filesshopizer · shopizer · CWE-79 | Средняя4,8 | — | 0,6 % | 1 мая 2022 г. |
18Наблюдать | CVE-2014-4965Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or Hshopizer · shopizer · CWE-79 | Средняя4,3 | — | 3,2 % | 15 июл. 2014 г. |
- CVE-2022-2306335Наблюдать
Shopizer - Insufficient Session Expiration
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %shopizer · shopizer3 мая 2022 г.
- CVE-2025-5160532Наблюдать
An issue was discovered in Shopizer 3.2.7.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %shopizer · shopizer22 авг. 2025 г.
- CVE-2014-496328Наблюдать
Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter t
СредняяCVSS 6,8Proof of conceptEPSS 4 %shopizer · shopizer15 июл. 2014 г.
- CVE-2014-496428Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication
СредняяCVSS 6,8Proof of conceptEPSS 2 %shopizer · shopizer15 июл. 2014 г.
- CVE-2014-496226Наблюдать
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuant
СредняяCVSS 6,4Proof of conceptEPSS 5 %shopizer · shopizer15 июл. 2014 г.
- CVE-2022-2306126Наблюдать
Shopizer - IDOR delete superadmin
СредняяCVSS 6,5Эксплойта нетEPSS 1 %shopizer · shopizer1 мая 2022 г.
- CVE-2020-1100726Наблюдать
Negative charge in shopping cart possible in Shopizer
СредняяCVSS 6,5Эксплойта нетEPSS 1 %shopizer · shopizer16 апр. 2020 г.
- CVE-2020-1100621Наблюдать
Potential remote code execution in Shopizer
СредняяCVSS 5,4Эксплойта нетEPSS 1 %shopizer · shopizer8 мая 2020 г.
- CVE-2021-3356220Наблюдать
A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,8Proof of conceptEPSS 3 %shopizer · shopizer24 мая 2021 г.
- CVE-2021-3356120Наблюдать
A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML v
СредняяCVSS 4,8Proof of conceptEPSS 3 %shopizer · shopizer24 мая 2021 г.
- CVE-2014-538520Наблюдать
com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, w
СредняяCVSS 5,0Эксплойта нетEPSS 1 %shopizer · shopizer21 авг. 2014 г.
- CVE-2022-2305919Наблюдать
Shopizer - Stored XSS in Manage Images
СредняяCVSS 4,8Эксплойта нетEPSS 1 %shopizer · shopizer29 мар. 2022 г.
- CVE-2022-2306019Наблюдать
Shopizer - Stored XSS in Manage Files
СредняяCVSS 4,8Эксплойта нетEPSS 1 %shopizer · shopizer1 мая 2022 г.
- CVE-2014-496518Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or H
СредняяCVSS 4,3Proof of conceptEPSS 3 %shopizer · shopizer15 июл. 2014 г.