Known Vulnerabilities for Eshop by Oxid-esales
Listed below are 10 of the newest known vulnerabilities associated with "Eshop" by "Oxid-esales".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-38330 json | OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration... | 5.3 - MEDIUM | 2023-08-02 | 2023-08-08 |
| CVE-2022-35493 json | A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecom... | 5.3 - MEDIUM | 2022-08-08 | 2026-07-08 |
| CVE-2019-17062 json | An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.... | 8.8 - HIGH | 2019-11-05 | 2019-11-08 |
| CVE-2019-13026 json | OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an att... | 9.8 - CRITICAL | 2019-07-30 | 2019-08-07 |
| CVE-2018-20715 json | The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxCo... | 9.8 - CRITICAL | 2019-01-15 | 2023-11-07 |
| CVE-2018-12579 json | An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Profession... | 8.1 - HIGH | 2018-08-20 | 2018-11-07 |
| CVE-2018-5763 json | An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URL... | 5.9 - MEDIUM | 2018-02-19 | 2018-03-20 |
| CVE-2017-14993 json | OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (leg... | 7.5 - HIGH | 2018-02-20 | 2019-10-03 |
| CVE-2017-12415 json | OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (leg... | 7.5 - HIGH | 2018-02-20 | 2018-03-16 |
| CVE-2015-6926 json | The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate user... | 7.5 - HIGH | 2018-01-19 | 2021-01-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oxid-esales | Eshop | 6.1.5 | |||
| Application | Oxid-esales | Eshop | 6.1.5 | |||
| Application | Oxid-esales | Eshop | 6.1.5 | |||
| Application | Oxid-esales | Eshop | 6.1.0 | |||
| Application | Oxid-esales | Eshop | 6.1.0 | |||
| Application | Oxid-esales | Eshop | 6.1.0 | |||
| Application | Oxid-esales | Eshop | 6.0.6 | |||
| Application | Oxid-esales | Eshop | 6.0.6 | |||
| Application | Oxid-esales | Eshop | 6.0.6 | |||
| Application | Oxid-esales | Eshop | 6.0.0 | |||
| Application | Oxid-esales | Eshop | 6.0.0 | |||
| Application | Oxid-esales | Eshop | 6.0.0 | |||
| Application | Oxid-esales | Eshop | 6.0.0 | |||
| Application | Oxid-esales | Eshop | 6.0.0 | |||
| Application | Oxid-esales | Eshop | 6.0.0 | |||
| Application | Oxid-esales | Eshop | 5.3.5 | |||
| Application | Oxid-esales | Eshop | 5.3.4 | |||
| Application | Oxid-esales | Eshop | 5.3.3 | |||
| Application | Oxid-esales | Eshop | 5.3.2 | |||
| Application | Oxid-esales | Eshop | 5.3.1 |