Known Vulnerabilities for X-cart by Qualiteam
Listed below are 10 of the newest known vulnerabilities associated with "X-cart" by "Qualiteam".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105573 json | A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/ac... | Not Provided | 2026-10-06 | 2026-10-06 |
| CVE-2026-104119 json | The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting th... | Not Provided | 2026-10-04 | 2026-10-05 |
| CVE-2026-103888 json | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-102775 json | Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1... | Not Provided | 2026-10-05 | 2026-10-05 |
| CVE-2026-100872 json | Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated ... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-100748 json | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | Not Provided | 2026-09-27 | 2026-09-29 |
| CVE-2026-94462 json | Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/c... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-93617 json | Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injectio... | Not Provided | 2026-10-05 | 2026-10-06 |
| CVE-2026-92437 json | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check befo... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-92436 json | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading ... | Not Provided | 2026-09-27 | 2026-09-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Qualiteam | X-cart | 5.4.1.5 | |||
| Application | Qualiteam | X-cart | 5.4.1.4 | |||
| Application | Qualiteam | X-cart | 5.4.1.3 | |||
| Application | Qualiteam | X-cart | 5.4.1.2 | |||
| Application | Qualiteam | X-cart | 5.4.1.1 | |||
| Application | Qualiteam | X-cart | 5.4.1.0 | |||
| Application | Qualiteam | X-cart | 5.4.0.9 | |||
| Application | Qualiteam | X-cart | 5.4.0.8 | |||
| Application | Qualiteam | X-cart | 5.4.0.7 | |||
| Application | Qualiteam | X-cart | 5.4.0.6 | |||
| Application | Qualiteam | X-cart | 5.4.0.5 | |||
| Application | Qualiteam | X-cart | 5.4.0.4 | |||
| Application | Qualiteam | X-cart | 5.4.0.3 | |||
| Application | Qualiteam | X-cart | 5.4.0.2 | |||
| Application | Qualiteam | X-cart | 5.4.0.11 | |||
| Application | Qualiteam | X-cart | 5.4.0.10 | |||
| Application | Qualiteam | X-cart | 5.3.6.6 | |||
| Application | Qualiteam | X-cart | 5.3.6.5 | |||
| Application | Qualiteam | X-cart | 5.3.6.4 | |||
| Application | Qualiteam | X-cart | 5.3.6.3 |