Oscommerce

Oscommerce

78 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Published 16.09.2025 14:33:40
  • Last modified 17.09.2025 14:18:55

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauth...

  • EPSS 0.07%
  • Published 17.06.2025 08:50:17
  • Last modified 17.06.2025 20:50:23

Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the name of any parameter in /watch/en/about-us. This vulnerab...

  • EPSS 15.6%
  • Published 30.04.2024 22:15:07
  • Last modified 21.11.2024 09:42:40

A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the argument cat leads to cross site scripting. It is possible to launch the attac...

Exploit
  • EPSS 0.02%
  • Published 21.03.2024 04:15:09
  • Last modified 27.06.2025 15:21:43

An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

  • EPSS 0.03%
  • Published 08.12.2023 15:15:08
  • Last modified 21.11.2024 08:44:11

A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the file /b2b-supermarket/catalog/all-products. The manipulation of the argument keywords with the input %27%22%3E%3Cimg%2Fsrc%3D1+onerr...

Exploit
  • EPSS 0.29%
  • Published 07.12.2023 22:15:08
  • Last modified 21.11.2024 08:44:08

A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argume...

  • EPSS 0.11%
  • Published 26.11.2023 22:15:06
  • Last modified 21.11.2024 08:43:33

A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /catalog/compare of the component Instant Message Handler. The manipulation of the argument compare with the...

Exploit
  • EPSS 0.12%
  • Published 30.09.2023 23:15:40
  • Last modified 21.11.2024 08:24:41

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

Exploit
  • EPSS 0.12%
  • Published 30.09.2023 23:15:40
  • Last modified 21.11.2024 08:24:41

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tax_class_title" parameter, potentially leading to unauthorized execution of scripts within a user's web...

Exploit
  • EPSS 0.12%
  • Published 30.09.2023 23:15:40
  • Last modified 21.11.2024 08:24:41

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "company_address" parameter, potentially leading to unauthorized execution of scripts within a user's web...