Known Vulnerabilities for products from Oxid-esales
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Oxid-esales".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-38330 json | OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration... | 5.3 - MEDIUM | 2023-08-02 | 2023-08-08 |
| CVE-2019-17062 json | An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.... | 8.8 - HIGH | 2019-11-05 | 2019-11-08 |
| CVE-2019-13026 json | OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an att... | 9.8 - CRITICAL | 2019-07-30 | 2019-08-07 |
| CVE-2018-20715 json | The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxCo... | 9.8 - CRITICAL | 2019-01-15 | 2023-11-07 |
| CVE-2018-12579 json | An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Profession... | 8.1 - HIGH | 2018-08-20 | 2018-11-07 |
| CVE-2018-5763 json | An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URL... | 5.9 - MEDIUM | 2018-02-19 | 2018-03-20 |
| CVE-2017-14993 json | OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (leg... | 7.5 - HIGH | 2018-02-20 | 2019-10-03 |
| CVE-2017-12415 json | OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (leg... | 7.5 - HIGH | 2018-02-20 | 2018-03-16 |
| CVE-2015-6926 json | The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate user... | 7.5 - HIGH | 2018-01-19 | 2021-01-19 |
| CVE-2014-4919 json | OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7... | 5.4 - MEDIUM | 2018-01-19 | 2021-01-19 |
| CVE-2014-2016 json | Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x... | Not Provided | 2014-03-25 | 2026-05-06 |
| CVE-2013-5913 json | Cross-site scripting (XSS) vulnerability in the getRecommSearch function in recommlist.php in OXID eShop before 4.6.7, Profes... | Not Provided | 2013-10-15 | 2026-04-29 |
Known software with vulnerabilities from Oxid-esales
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Oxid-esales | Eshop | 4.10.0 |