Known Vulnerabilities for products from Oxidforge
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Oxidforge".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-26260 json | OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's acco... | 5.4 - MEDIUM | 2023-04-11 | 2023-04-19 |
| CVE-2016-5072 json | OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class.... | Not Provided | 2017-04-10 | 2025-04-20 |
| CVE-2014-2017 json | CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition befo... | 6.1 - MEDIUM | 2018-01-18 | 2018-02-06 |
| CVE-2009-3112 json | Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers ... | Not Provided | 2009-09-09 | 2026-04-23 |