CVE-2009-20006
- EPSS 0.05%
- Published 16.09.2025 14:33:40
- Last modified 17.09.2025 14:18:55
osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauth...
CVE-2025-40674
- EPSS 0.07%
- Published 17.06.2025 08:50:17
- Last modified 17.06.2025 20:50:23
Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the name of any parameter in /watch/en/about-us. This vulnerab...
- EPSS 15.6%
- Published 30.04.2024 22:15:07
- Last modified 21.11.2024 09:42:40
A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the argument cat leads to cross site scripting. It is possible to launch the attac...
CVE-2024-22724
- EPSS 0.02%
- Published 21.03.2024 04:15:09
- Last modified 27.06.2025 15:21:43
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.
CVE-2023-6609
- EPSS 0.03%
- Published 08.12.2023 15:15:08
- Last modified 21.11.2024 08:44:11
A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the file /b2b-supermarket/catalog/all-products. The manipulation of the argument keywords with the input %27%22%3E%3Cimg%2Fsrc%3D1+onerr...
CVE-2023-6579
- EPSS 0.29%
- Published 07.12.2023 22:15:08
- Last modified 21.11.2024 08:44:08
A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argume...
CVE-2023-6296
- EPSS 0.11%
- Published 26.11.2023 22:15:06
- Last modified 21.11.2024 08:43:33
A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /catalog/compare of the component Instant Message Handler. The manipulation of the argument compare with the...
CVE-2023-43734
- EPSS 0.12%
- Published 30.09.2023 23:15:40
- Last modified 21.11.2024 08:24:41
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-43732
- EPSS 0.12%
- Published 30.09.2023 23:15:40
- Last modified 21.11.2024 08:24:41
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tax_class_title" parameter, potentially leading to unauthorized execution of scripts within a user's web...
CVE-2023-43733
- EPSS 0.12%
- Published 30.09.2023 23:15:40
- Last modified 21.11.2024 08:24:41
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "company_address" parameter, potentially leading to unauthorized execution of scripts within a user's web...