osCommerce records
95 published records for vendor oscommerce.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')48
- CWE-20 Improper Input Validation7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
95 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2023-6579No exploit | osCommerce POST Parameter shopping-cart sql injectionoscommerce · oscommerce · CWE-89 | Critical9.8 | — | 24.0% | Dec 7, 2023 |
41Plan | CVE-2020-27976Proof of concept | osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely.oscommerce · oscommerce · CWE-78 | Critical9.8 | — | 7.0% | Oct 28, 2020 |
41Plan | CVE-2009-2039No exploit | Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.oscommerce · oscommerce | Critical10.0 | — | 1.8% | Jun 12, 2009 |
40Plan | CVE-2009-2038No exploit | Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank chargeoscommerce · oscommerce | Critical10.0 | — | 1.4% | Jun 12, 2009 |
39Monitor | CVE-2020-23360No exploit | oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the cheoscommerce · oscommerce · CWE-697 | Critical9.8 | — | 1.2% | Jan 27, 2021 |
35Monitor | CVE-2020-27975No exploit | osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.oscommerce · oscommerce · CWE-352 | High8.8 | — | 0.6% | Oct 28, 2020 |
35Monitor | CVE-2019-25497No exploit | osCommerce 2.3.4.1 SQL Injection via currency Parameteroscommerce · oscommerce · CWE-89 | High8.8 | — | 0.3% | Feb 27, 2026 |
35Monitor | CVE-2019-25496No exploit | osCommerce 2.3.4.1 SQL Injection via products_id Parameteroscommerce · oscommerce · CWE-89 | High8.8 | — | 0.3% | Feb 27, 2026 |
35Monitor | CVE-2019-25495No exploit | osCommerce 2.3.4.1 SQL Injection via reviews_id Parameteroscommerce · oscommerce · CWE-89 | High8.8 | — | 0.3% | Feb 27, 2026 |
33Monitor | CVE-2004-2044Proof of concept | PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke francisco burzi · php-nuke | High7.5 | — | 11.0% | Jun 1, 2004 |
32Monitor | CVE-2002-1991Proof of concept | PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.oscommerce · oscommerce · CWE-94 | High7.5 | — | 7.5% | Dec 31, 2002 |
31Monitor | CVE-2008-0719Proof of concept | SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 alloscommerce · customer testimonials · CWE-89 | High7.5 | — | 2.9% | Feb 11, 2008 |
31Monitor | CVE-2002-2019Proof of concept | PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a.oscommerce · oscommerce · CWE-94 | High7.5 | — | 2.6% | Dec 31, 2002 |
31Monitor | CVE-2011-4543No exploit | Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .oscommerce · oscommerce · CWE-22 | High7.5 | — | 2.6% | Dec 5, 2011 |
31Monitor | CVE-2006-6533No exploit | Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arboscommerce · oscommerce | High7.5 | — | 1.7% | Dec 13, 2006 |
30Monitor | CVE-2004-2638No exploit | The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the ioscommerce · oscommerce | High7.5 | — | 1.5% | Dec 31, 2004 |
30Monitor | CVE-2006-4297No exploit | SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQoscommerce · oscommerce | High7.5 | — | 1.5% | Aug 22, 2006 |
30Monitor | CVE-2007-1477No exploit | Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitroscommerce · php point of sale | High7.5 | — | 1.5% | Mar 16, 2007 |
30Monitor | CVE-2005-4677No exploit | SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers tooscommerce · oscommerce | High7.5 | — | 1.4% | Dec 31, 2005 |
30Monitor | CVE-2008-4765Proof of concept | SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands voscommerce · poll booth · CWE-89 | High7.5 | — | 1.0% | Oct 27, 2008 |
29Monitor | CVE-2018-18573No exploit | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.oscommerce · oscommerce · CWE-94 | High7.2 | — | 2.6% | Aug 22, 2019 |
29Monitor | CVE-2018-18572No exploit | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.oscommerce · oscommerce · CWE-434 | High7.2 | — | 2.5% | Aug 22, 2019 |
27Monitor | CVE-2014-10033Proof of concept | SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier alloscommerce · online merchant · CWE-89 | Medium6.5 | — | 1.8% | Jan 13, 2015 |
26Monitor | CVE-2024-22724No exploit | An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administroscommerce · oscommerce · CWE-94 | Medium6.6 | — | 0.3% | Mar 21, 2024 |
24Monitor | CVE-2020-12058No exploit | Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code.oscommerce · ce phoenix · CWE-79 | Medium6.1 | — | 1.0% | Sep 3, 2020 |
- CVE-2023-657946Plan
osCommerce POST Parameter shopping-cart sql injection
CriticalCVSS 9.8No exploitEPSS 24%oscommerce · oscommerceDec 7, 2023
- CVE-2020-2797641Plan
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely.
CriticalCVSS 9.8Proof of conceptEPSS 7%oscommerce · oscommerceOct 28, 2020
- CVE-2009-203941Plan
Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.
CriticalCVSS 10.0No exploitEPSS 2%oscommerce · oscommerceJun 12, 2009
- CVE-2009-203840Plan
Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charge
CriticalCVSS 10.0No exploitEPSS 1%oscommerce · oscommerceJun 12, 2009
- CVE-2020-2336039Monitor
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the che
CriticalCVSS 9.8No exploitEPSS 1%oscommerce · oscommerceJan 27, 2021
- CVE-2020-2797535Monitor
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
HighCVSS 8.8No exploitEPSS 1%oscommerce · oscommerceOct 28, 2020
- CVE-2019-2549735Monitor
osCommerce 2.3.4.1 SQL Injection via currency Parameter
HighCVSS 8.8No exploitEPSS 0%oscommerce · oscommerceFeb 27, 2026
- CVE-2019-2549635Monitor
osCommerce 2.3.4.1 SQL Injection via products_id Parameter
HighCVSS 8.8No exploitEPSS 0%oscommerce · oscommerceFeb 27, 2026
- CVE-2019-2549535Monitor
osCommerce 2.3.4.1 SQL Injection via reviews_id Parameter
HighCVSS 8.8No exploitEPSS 0%oscommerce · oscommerceFeb 27, 2026
- CVE-2004-204433Monitor
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke
HighCVSS 7.5Proof of conceptEPSS 11%francisco burzi · php-nukeJun 1, 2004
- CVE-2002-199132Monitor
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
HighCVSS 7.5Proof of conceptEPSS 7%oscommerce · oscommerceDec 31, 2002
- CVE-2008-071931Monitor
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 all
HighCVSS 7.5Proof of conceptEPSS 3%oscommerce · customer testimonialsFeb 11, 2008
- CVE-2002-201931Monitor
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a.
HighCVSS 7.5Proof of conceptEPSS 3%oscommerce · oscommerceDec 31, 2002
- CVE-2011-454331Monitor
Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .
HighCVSS 7.5No exploitEPSS 3%oscommerce · oscommerceDec 5, 2011
- CVE-2006-653331Monitor
Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arb
HighCVSS 7.5No exploitEPSS 2%oscommerce · oscommerceDec 13, 2006
- CVE-2004-263830Monitor
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the i
HighCVSS 7.5No exploitEPSS 2%oscommerce · oscommerceDec 31, 2004
- CVE-2006-429730Monitor
SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQ
HighCVSS 7.5No exploitEPSS 1%oscommerce · oscommerceAug 22, 2006
- CVE-2007-147730Monitor
Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitr
HighCVSS 7.5No exploitEPSS 1%oscommerce · php point of saleMar 16, 2007
- CVE-2005-467730Monitor
SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to
HighCVSS 7.5No exploitEPSS 1%oscommerce · oscommerceDec 31, 2005
- CVE-2008-476530Monitor
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands v
HighCVSS 7.5Proof of conceptEPSS 1%oscommerce · poll boothOct 27, 2008
- CVE-2018-1857329Monitor
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
HighCVSS 7.2No exploitEPSS 3%oscommerce · oscommerceAug 22, 2019
- CVE-2018-1857229Monitor
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
HighCVSS 7.2No exploitEPSS 3%oscommerce · oscommerceAug 22, 2019
- CVE-2014-1003327Monitor
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier all
MediumCVSS 6.5Proof of conceptEPSS 2%oscommerce · online merchantJan 13, 2015
- CVE-2024-2272426Monitor
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administr
MediumCVSS 6.6No exploitEPSS 0%oscommerce · oscommerceMar 21, 2024
- CVE-2020-1205824Monitor
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code.
MediumCVSS 6.1No exploitEPSS 1%oscommerce · ce phoenixSep 3, 2020