Known Vulnerabilities for products from Shopizer
Listed below are 13 of the newest known vulnerabilities associated with the vendor "Shopizer".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-36767 json | Not Provided | 2026-04-30 | 2026-04-30 | |
| CVE-2026-36766 json | Not Provided | 2026-04-30 | 2026-04-30 | |
| CVE-2022-23063 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2022-05-03 | 2022-05-10 |
| CVE-2022-23061 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2022-05-01 | 2022-05-09 |
| CVE-2022-23060 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.8 - MEDIUM | 2022-05-01 | 2022-05-09 |
| CVE-2022-23059 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.8 - MEDIUM | 2022-03-29 | 2022-04-08 |
| CVE-2021-33562 json | A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary we... | 4.8 - MEDIUM | 2021-05-24 | 2021-05-27 |
| CVE-2021-33561 json | A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web s... | 4.8 - MEDIUM | 2021-05-24 | 2021-05-27 |
| CVE-2020-11007 json | In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence... | 6.5 - MEDIUM | 2020-04-16 | 2020-04-29 |
| CVE-2020-11006 json | In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when in... | 5.4 - MEDIUM | 2020-05-08 | 2020-05-13 |
| CVE-2014-5385 json | com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authenticat... | Not Provided | 2014-08-21 | 2026-05-06 |
| CVE-2014-4965 json | Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary ... | Not Provided | 2014-07-15 | 2026-05-06 |
| CVE-2014-4964 json | Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the... | Not Provided | 2014-07-15 | 2026-05-06 |
| CVE-2014-4963 json | Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.custome... | Not Provided | 2014-07-15 | 2026-05-06 |
| CVE-2014-4962 json | Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in t... | Not Provided | 2014-07-15 | 2026-05-06 |
Known software with vulnerabilities from Shopizer
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Shopizer | Shopizer | 1.1.5 |