Known Vulnerabilities for Ecommerce by Conectiva
Listed below are 10 of the newest known vulnerabilities associated with "Ecommerce" by "Conectiva".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-76128 json | The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribu... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-59536 json | Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-57414 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot fo... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-57360 json | Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions. | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-53639 json | Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-53638 json | Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-53637 json | Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 throu... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-52698 json | Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2.3 ... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-52693 json | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49228 json | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvv... | Not Provided | 2026-08-18 | 2026-08-18 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Conectiva | Ecommerce | - |