Skip to content
Noroxi

shopwind records

7 published records for vendor shopwind.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

7 records
  • ShopWind <= 3.4.2 has a RCE vulnerability in Database.php

    CriticalCVSS 9.8No exploitEPSS 16%

    shopwind · shopwindMay 11, 2022

  • CVE-2024-1705
    32Monitor

    Shopwind Installation DefaultController.php actionCreate code injection

    HighCVSS 8.1No exploitEPSS 1%

    shopwind · shopwindFeb 21, 2024

  • ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php

    HighCVSS 7.2No exploitEPSS 1%

    shopwind · shopwindMay 11, 2022

  • Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbContro

    MediumCVSS 6.5No exploitEPSS 1%

    shopwind · shopwindMay 11, 2022

  • Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.

    MediumCVSS 6.1No exploitEPSS 0%

    shopwind · shopwindNov 9, 2022

  • Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbCont

    MediumCVSS 5.3No exploitEPSS 1%

    shopwind · shopwindMay 11, 2022

  • Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.

    MediumCVSS 5.4No exploitEPSS 0%

    shopwind · shopwindMay 11, 2022