Known Vulnerabilities for Zen Cart by Zen-cart
Listed below are 10 of the newest known vulnerabilities associated with "Zen Cart" by "Zen-cart".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103888 json | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-100872 json | Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated ... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-100748 json | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | Not Provided | 2026-09-27 | 2026-09-29 |
| CVE-2026-94462 json | Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/c... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-92437 json | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check befo... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-92436 json | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading ... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-91020 json | The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount ser... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-85350 json | The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Toget... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-85037 json | The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-85010 json | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when i... | Not Provided | 2026-09-21 | 2026-09-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zen-cart | Zen Cart | 2008 | |||
| Application | Zen-cart | Zen Cart | 1.6.0 | |||
| Application | Zen-cart | Zen Cart | 1.5.7b | |||
| Application | Zen-cart | Zen Cart | 1.5.7a | |||
| Application | Zen-cart | Zen Cart | 1.5.7 | |||
| Application | Zen-cart | Zen Cart | 1.5.6c | |||
| Application | Zen-cart | Zen Cart | 1.5.6b | |||
| Application | Zen-cart | Zen Cart | 1.5.6a | |||
| Application | Zen-cart | Zen Cart | 1.5.6 | |||
| Application | Zen-cart | Zen Cart | 1.5.5f | |||
| Application | Zen-cart | Zen Cart | 1.5.5e | |||
| Application | Zen-cart | Zen Cart | 1.5.5d | |||
| Application | Zen-cart | Zen Cart | 1.5.5c | |||
| Application | Zen-cart | Zen Cart | 1.5.5b | |||
| Application | Zen-cart | Zen Cart | 1.5.5a | |||
| Application | Zen-cart | Zen Cart | 1.5.5 | |||
| Application | Zen-cart | Zen Cart | 1.5.4 | |||
| Application | Zen-cart | Zen Cart | 1.5.3 | |||
| Application | Zen-cart | Zen Cart | 1.5.3 | |||
| Application | Zen-cart | Zen Cart | 1.5.2 |