cpcommerce records
10 published records for vendor cpcommerce.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2008-1908Proof of concept | Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .cpcommerce · cpcommerce · CWE-22 | High7.5 | — | 2.8% | Apr 22, 2008 |
30Monitor | CVE-2007-2890Proof of concept | SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via thcpcommerce · cpcommerce | High7.5 | — | 1.2% | May 29, 2007 |
30Monitor | CVE-2007-2959Proof of concept | SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via thecpcommerce · cpcommerce | High7.5 | — | 1.2% | May 31, 2007 |
30Monitor | CVE-2008-1907Proof of concept | Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQcpcommerce · cpcommerce · CWE-89 | High7.5 | — | 1.0% | Apr 22, 2008 |
30Monitor | CVE-2009-1345Proof of concept | SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_documencpcommerce · cpcommerce · CWE-89 | High7.5 | — | 1.0% | Apr 20, 2009 |
28Monitor | CVE-2003-1500No exploit | PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the preficpcommerce · cpcommerce · CWE-94 | Medium6.8 | — | 3.0% | Dec 31, 2003 |
18Monitor | CVE-2008-1906Proof of concept | Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML cpcommerce · cpcommerce · CWE-79 | Medium4.3 | — | 1.7% | Apr 22, 2008 |
17Monitor | CVE-2008-4121No exploit | Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTMLcpcommerce · cpcommerce · CWE-79 | Medium4.3 | — | 1.3% | Oct 21, 2008 |
17Monitor | CVE-2007-2968No exploit | Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web scrcpcommerce · cpcommerce | Medium4.3 | — | 1.2% | May 31, 2007 |
17Monitor | CVE-2008-4637No exploit | Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknocpcommerce · cpcommerce · CWE-79 | Medium4.3 | — | 0.8% | Oct 21, 2008 |
- CVE-2008-190831Monitor
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .
HighCVSS 7.5Proof of conceptEPSS 3%cpcommerce · cpcommerceApr 22, 2008
- CVE-2007-289030Monitor
SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via th
HighCVSS 7.5Proof of conceptEPSS 1%cpcommerce · cpcommerceMay 29, 2007
- CVE-2007-295930Monitor
SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%cpcommerce · cpcommerceMay 31, 2007
- CVE-2008-190730Monitor
Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQ
HighCVSS 7.5Proof of conceptEPSS 1%cpcommerce · cpcommerceApr 22, 2008
- CVE-2009-134530Monitor
SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_documen
HighCVSS 7.5Proof of conceptEPSS 1%cpcommerce · cpcommerceApr 20, 2009
- CVE-2003-150028Monitor
PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefi
MediumCVSS 6.8No exploitEPSS 3%cpcommerce · cpcommerceDec 31, 2003
- CVE-2008-190618Monitor
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3Proof of conceptEPSS 2%cpcommerce · cpcommerceApr 22, 2008
- CVE-2008-412117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3No exploitEPSS 1%cpcommerce · cpcommerceOct 21, 2008
- CVE-2007-296817Monitor
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web scr
MediumCVSS 4.3No exploitEPSS 1%cpcommerce · cpcommerceMay 31, 2007
- CVE-2008-463717Monitor
Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unkno
MediumCVSS 4.3No exploitEPSS 1%cpcommerce · cpcommerceOct 21, 2008