Home/Product/oscommerce
Product

oscommerce

91 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-25497
<= 2.3.4.1
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by
8.2HIGH
CVE-2019-25496
all versions
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by
8.2HIGH
CVE-2019-25495
all versions
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by
8.2HIGH
CVE-2024-22724
all versions
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via
6.6MEDIUM
CVE-2023-6609
all versions
A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the file /b2b-su
3.5LOW
CVE-2023-6579
all versions
A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown function
7.3HIGH
CVE-2023-6296
all versions
A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown functionality
4.3MEDIUM
CVE-2023-5112
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-5111
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43735
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43734
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43733
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43732
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43731
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43730
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43729
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43728
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43727
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43726
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43725
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43724
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43723
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43722
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43721
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43720
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43719
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43718
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43717
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43716
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43715
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43714
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43713
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "t
5.4MEDIUM
CVE-2023-43712
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43711
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43710
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43709
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43708
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43707
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43706
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43705
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43704
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43703
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2023-43702
all versions
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject
5.4MEDIUM
CVE-2022-35212
< 2.3.4.1
osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().
6.1MEDIUM
CVE-2020-23360
all versions
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypa
9.8CRITICAL
CVE-2020-29070
all versions
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters
4.8MEDIUM
CVE-2020-27976
< 1.0.5.4
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be pas
9.8CRITICAL
CVE-2020-27975
< 1.0.5.4
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
8.8HIGH
CVE-2020-12058
all versions
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript c
6.1MEDIUM
CVE-2018-18573
all versions
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrator
7.2HIGH
CVE-2018-18572
all versions
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script fil
7.2HIGH
CVE-2018-18966
all versions
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/imag
4.9MEDIUM
CVE-2018-18965
all versions
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/imag
4.9MEDIUM
CVE-2018-18964
all versions
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/imag
4.9MEDIUM
CVE-2015-2965
<= 2.2ms1j-r8
Directory traversal vulnerability in osCommerce Japanese 2.2ms1j-R8 and earlier allows remote authenticated administrators to read
CVE-2014-10033
<= 2.3.3.4
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and e
CVE-2012-5798
all versions
The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Com
CVE-2012-5797
all versions
The PayPal Pro PayFlow module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common
CVE-2012-5796
all versions
The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (C
CVE-2012-5795
all versions
The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Nam
CVE-2012-5794
all versions
The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name
CVE-2012-5793
all versions
The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name
CVE-2012-5792
all versions
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Na
CVE-2012-2991
<= 2.3.3
The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attacke
CVE-2012-2935
all versions
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommerce Online
CVE-2012-1792
all versions
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online
CVE-2012-1059
all versions
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merc
CVE-2012-0312
all versions
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remo
CVE-2012-0311
all versions
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9 allows remote attackers to inject arbitrary web script or
CVE-2011-4543
all versions
Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local fil
CVE-2011-3767
all versions
osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in
CVE-2009-2039
all versions
Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to ord
CVE-2009-2038
all versions
Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to b
CVE-2009-0408
all versions
Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of ad
CVE-2008-4170
all versions
create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, w
CVE-2008-0719
all versions
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Mercha
CVE-2007-1477
all versions
Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and exec
CVE-2006-6534
all versions
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 3.0a3 allow remote attackers to inject arbitrary web script or H
CVE-2006-6533
all versions
Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and e
CVE-2006-5190
<= 2.2_ms2_2006-08-17
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject a
CVE-2006-4298
all versions
Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to de
CVE-2006-4297
all versions
SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute ar
CVE-2005-2330
all versions
Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .
CVE-2005-1951
all versions
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web con
CVE-2005-0458
all versions
Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web s
CVE-2004-2638
all versions
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modif
CVE-2004-2021
all versions
Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (
CVE-2004-2044
all versions
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and
CVE-2003-1219
<= 2.2_ms2
Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows rem
CVE-2002-2019
all versions
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to
CVE-2002-1991
all versions
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
threatengine.sh