shopizer
Web & CMS Pluginscommercial
Top products
Latest CVEs
The 14 most recently published vulnerabilities affecting shopizer.
- CVE-2025-51605An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, wh...8.1
- CVE-2022-23063Shopizer - Insufficient Session Expiration8.8
- CVE-2022-23061Shopizer - IDOR delete superadmin6.5
- CVE-2022-23060Shopizer - Stored XSS in Manage Files4.8
- CVE-2022-23059Shopizer - Stored XSS in Manage Images4.8
- CVE-2021-33561A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration...4.8
- CVE-2021-33562A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary prod...4.8
- CVE-2020-11006Potential remote code execution in Shopizer9.1
- CVE-2020-11007Negative charge in shopping cart possible in Shopizer6.5
- CVE-2014-5385com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which makes it easier for remote attackers to guess passwo...5.0
- CVE-2014-4965Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) customername parameter to central/orders/...4.3
- CVE-2014-4963Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.6.8
- CVE-2014-4964Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users for requests that (1) modify customer settings ...6.8
- CVE-2014-4962Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be s...6.4