ec-cube records
40 published records for vendor ec-cube.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 17.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-20 Improper Input Validation2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-4837No exploit | SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via uec-cube · discount coupon · CWE-89 | Critical9.8 | — | 2.1% | Jul 31, 2016 |
39Monitor | CVE-2022-37346No exploit | EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files.ec-cube · product image bulk upload · CWE-434 | Critical9.8 | — | 1.2% | Sep 27, 2022 |
33Monitor | CVE-2020-5590No exploit | Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary fiec-cube · ec-cube · CWE-22 | High8.1 | — | 2.1% | Jun 19, 2020 |
31Monitor | CVE-2021-20778No exploit | Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sec-cube · ec-cube | High7.5 | — | 2.1% | Jul 1, 2021 |
30Monitor | CVE-2020-5680No exploit | Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS)ec-cube · ec-cube · CWE-20 | High7.5 | — | 1.4% | Dec 3, 2020 |
30Monitor | CVE-2008-4534No exploit | SQL injection vulnerability in EC-CUBE Ver2 2.1.2a and earlier, and Ver2 RC 2.3.0-rc1 and earlier, allows remote attackers to execute arbitrec-cube · ec-cube · CWE-89 | High7.5 | — | 1.3% | Oct 10, 2008 |
30Monitor | CVE-2008-4991No exploit | SQL injection vulnerability in LOCKON CO.,LTD.ec-cube · ec-cube · CWE-89 | High7.5 | — | 1.1% | Nov 6, 2008 |
28Monitor | CVE-2023-46845No exploit | EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execec-cube · ec-cube · CWE-94 | High7.2 | — | 1.6% | Nov 7, 2023 |
28Monitor | CVE-2018-0658No exploit | Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) version 2.3.17 and earlierec-cube · ec-cube payment module · CWE-20 | High7.2 | — | 1.0% | Sep 7, 2018 |
28Monitor | CVE-2024-41924No exploit | Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series.ec-cube co.,ltd. · ec-cube 4 series · CWE-349 | High7.2 | — | 0.3% | Jul 30, 2024 |
27Monitor | CVE-2026-30777No exploit | EC-CUBE provided by EC-CUBE CO.,LTD.ec-cube · ec-cube · CWE-288 | Medium6.9 | — | 0.6% | Mar 5, 2026 |
26Monitor | CVE-2021-20841No exploit | Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access reec-cube · ec-cube | Medium6.5 | — | 1.3% | Nov 24, 2021 |
26Monitor | CVE-2021-20842No exploit | Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication oec-cube · ec-cube · CWE-352 | Medium6.5 | — | 0.6% | Nov 24, 2021 |
25Monitor | CVE-2021-20717Proof of concept | Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific iec-cube · ec-cube · CWE-79 | Medium6.1 | — | 2.3% | May 10, 2021 |
24Monitor | CVE-2016-1180No exploit | Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows remote attackercyber-will · social-button premium · CWE-79 | Medium6.1 | — | 1.6% | Apr 8, 2016 |
24Monitor | CVE-2021-20750No exploit | Cross-site scripting vulnerability in EC-CUBE EC-CUBE 3.0.0 to 3.0.18-p2 (EC-CUBE 3 series) and EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series)ec-cube · ec-cube · CWE-79 | Medium6.1 | — | 1.6% | Jun 27, 2021 |
24Monitor | CVE-2018-16191No exploit | Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.ec-cube · ec-cube · CWE-601 | Medium6.1 | — | 1.3% | Jan 9, 2019 |
24Monitor | CVE-2021-20735No exploit | Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip numbec-cube · delivery slip number · CWE-79 | Medium6.1 | — | 1.1% | Jun 21, 2021 |
24Monitor | CVE-2021-20751No exploit | Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary sec-cube · ec-cube · CWE-79 | Medium6.1 | — | 1.1% | Jun 27, 2021 |
24Monitor | CVE-2019-6003No exploit | Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remote attackers to injeec-cube · amazon pay · CWE-79 | Medium6.1 | — | 1.0% | Sep 12, 2019 |
24Monitor | CVE-2021-20828No exploit | Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inec-cube · ec-cube · CWE-79 | Medium6.1 | — | 0.8% | Sep 16, 2021 |
24Monitor | CVE-2021-20742No exploit | Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a ec-cube · business form output · CWE-79 | Medium6.1 | — | 0.8% | Jun 21, 2021 |
24Monitor | CVE-2021-20825No exploit | Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and earlier allows a remoec-cube · ec-cube · CWE-79 | Medium6.1 | — | 0.8% | Sep 16, 2021 |
24Monitor | CVE-2021-20744No exploit | Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remec-cube · business form output · CWE-79 | Medium6.1 | — | 0.8% | Jun 21, 2021 |
24Monitor | CVE-2021-20743No exploit | Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 aec-cube · email newsletters management · CWE-79 | Medium6.1 | — | 0.8% | Jun 21, 2021 |
- CVE-2016-483740Plan
SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via u
CriticalCVSS 9.8No exploitEPSS 2%ec-cube · discount couponJul 31, 2016
- CVE-2022-3734639Monitor
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files.
CriticalCVSS 9.8No exploitEPSS 1%ec-cube · product image bulk uploadSep 27, 2022
- CVE-2020-559033Monitor
Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary fi
HighCVSS 8.1No exploitEPSS 2%ec-cube · ec-cubeJun 19, 2020
- CVE-2021-2077831Monitor
Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain s
HighCVSS 7.5No exploitEPSS 2%ec-cube · ec-cubeJul 1, 2021
- CVE-2020-568030Monitor
Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS)
HighCVSS 7.5No exploitEPSS 1%ec-cube · ec-cubeDec 3, 2020
- CVE-2008-453430Monitor
SQL injection vulnerability in EC-CUBE Ver2 2.1.2a and earlier, and Ver2 RC 2.3.0-rc1 and earlier, allows remote attackers to execute arbitr
HighCVSS 7.5No exploitEPSS 1%ec-cube · ec-cubeOct 10, 2008
- CVE-2008-499130Monitor
SQL injection vulnerability in LOCKON CO.,LTD.
HighCVSS 7.5No exploitEPSS 1%ec-cube · ec-cubeNov 6, 2008
- CVE-2023-4684528Monitor
EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code exec
HighCVSS 7.2No exploitEPSS 2%ec-cube · ec-cubeNov 7, 2023
- CVE-2018-065828Monitor
Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) version 2.3.17 and earlier
HighCVSS 7.2No exploitEPSS 1%ec-cube · ec-cube payment moduleSep 7, 2018
- CVE-2024-4192428Monitor
Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series.
HighCVSS 7.2No exploitEPSS 0%ec-cube co.,ltd. · ec-cube 4 seriesJul 30, 2024
- CVE-2026-3077727Monitor
EC-CUBE provided by EC-CUBE CO.,LTD.
MediumCVSS 6.9No exploitEPSS 1%ec-cube · ec-cubeMar 5, 2026
- CVE-2021-2084126Monitor
Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access re
MediumCVSS 6.5No exploitEPSS 1%ec-cube · ec-cubeNov 24, 2021
- CVE-2021-2084226Monitor
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication o
MediumCVSS 6.5No exploitEPSS 1%ec-cube · ec-cubeNov 24, 2021
- CVE-2021-2071725Monitor
Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific i
MediumCVSS 6.1Proof of conceptEPSS 2%ec-cube · ec-cubeMay 10, 2021
- CVE-2016-118024Monitor
Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows remote attacker
MediumCVSS 6.1No exploitEPSS 2%cyber-will · social-button premiumApr 8, 2016
- CVE-2021-2075024Monitor
Cross-site scripting vulnerability in EC-CUBE EC-CUBE 3.0.0 to 3.0.18-p2 (EC-CUBE 3 series) and EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series)
MediumCVSS 6.1No exploitEPSS 2%ec-cube · ec-cubeJun 27, 2021
- CVE-2018-1619124Monitor
Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.
MediumCVSS 6.1No exploitEPSS 1%ec-cube · ec-cubeJan 9, 2019
- CVE-2021-2073524Monitor
Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip numb
MediumCVSS 6.1No exploitEPSS 1%ec-cube · delivery slip numberJun 21, 2021
- CVE-2021-2075124Monitor
Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary s
MediumCVSS 6.1No exploitEPSS 1%ec-cube · ec-cubeJun 27, 2021
- CVE-2019-600324Monitor
Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remote attackers to inje
MediumCVSS 6.1No exploitEPSS 1%ec-cube · amazon paySep 12, 2019
- CVE-2021-2082824Monitor
Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to in
MediumCVSS 6.1No exploitEPSS 1%ec-cube · ec-cubeSep 16, 2021
- CVE-2021-2074224Monitor
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a
MediumCVSS 6.1No exploitEPSS 1%ec-cube · business form outputJun 21, 2021
- CVE-2021-2082524Monitor
Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and earlier allows a remo
MediumCVSS 6.1No exploitEPSS 1%ec-cube · ec-cubeSep 16, 2021
- CVE-2021-2074424Monitor
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a rem
MediumCVSS 6.1No exploitEPSS 1%ec-cube · business form outputJun 21, 2021
- CVE-2021-2074324Monitor
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 a
MediumCVSS 6.1No exploitEPSS 1%ec-cube · email newsletters managementJun 21, 2021