Known Vulnerabilities for products from Shopxo
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Shopxo".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-12204 json | Not Provided | 2026-06-15 | 2026-06-15 | |
| CVE-2022-28056 json | ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/contr... | 9.8 - CRITICAL | 2022-05-02 | 2023-08-08 |
| CVE-2021-41938 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2022-05-19 | 2022-05-26 |
| CVE-2021-27817 json | A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where ... | 9.8 - CRITICAL | 2021-03-15 | 2021-03-18 |
| CVE-2020-26008 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2022-03-20 | 2022-03-28 |
| CVE-2020-26007 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2022-03-20 | 2022-03-28 |
| CVE-2020-24220 json | ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and g... | 8.8 - HIGH | 2020-08-17 | 2020-08-24 |
| CVE-2020-19778 json | Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulati... | 9.8 - CRITICAL | 2021-04-14 | 2022-10-05 |
| CVE-2019-5887 json | An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not check... | 7.5 - HIGH | 2019-01-10 | 2019-01-18 |
| CVE-2019-5886 json | An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock fi... | 9.8 - CRITICAL | 2019-01-10 | 2020-08-24 |
Known software with vulnerabilities from Shopxo
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Shopxo | Shopxo | 1.0.0 |