CVE-2026-105056
- EPSS 0.13%
- Veröffentlicht 05.10.2026 08:46:55
- Zuletzt bearbeitet 06.10.2026 15:04:25
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2...
CVE-2026-96344
- EPSS 0.37%
- Veröffentlicht 30.09.2026 12:27:19
- Zuletzt bearbeitet 30.09.2026 14:18:08
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
CVE-2026-76128
- EPSS 0.21%
- Veröffentlicht 25.08.2026 09:27:52
- Zuletzt bearbeitet 28.09.2026 23:10:00
The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it pos...
CVE-2026-57360
- EPSS 0.19%
- Veröffentlicht 02.07.2026 11:15:20
- Zuletzt bearbeitet 02.07.2026 15:17:09
Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.
CVE-2026-52693
- EPSS 0.29%
- Veröffentlicht 15.06.2026 20:19:30
- Zuletzt bearbeitet 15.06.2026 21:24:32
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
CVE-2025-49331
- EPSS 0.44%
- Veröffentlicht 17.06.2025 15:01:22
- Zuletzt bearbeitet 23.04.2026 15:31:28
Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue affects eCommerce Product Catalog: from n/a through <= 3.4.3.
CVE-2024-32558
- EPSS 0.37%
- Veröffentlicht 18.04.2024 10:15:09
- Zuletzt bearbeitet 28.04.2026 19:24:46
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog allows Reflected XSS.This issue affects eCommerce Product Catalog: from n/a through 3.3.32.
CVE-2024-32437
- EPSS 0.21%
- Veröffentlicht 15.04.2024 09:15:12
- Zuletzt bearbeitet 28.04.2026 19:24:38
Cross-Site Request Forgery (CSRF) vulnerability in impleCode eCommerce Product Catalog.This issue affects eCommerce Product Catalog: from n/a through 3.3.28.
CVE-2023-51688
- EPSS 0.48%
- Veröffentlicht 29.12.2023 15:15:10
- Zuletzt bearbeitet 28.04.2026 19:22:55
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3.26.
CVE-2023-5979
- EPSS 0.28%
- Veröffentlicht 04.12.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:54
The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products