Virtuemart

Virtuemart

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 25.10.2025 18:34:46
  • Zuletzt bearbeitet 27.10.2025 16:15:41

A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.

  • EPSS 0.25%
  • Veröffentlicht 11.06.2025 16:26:47
  • Zuletzt bearbeitet 12.06.2025 16:06:20

An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code e...

  • EPSS 0.04%
  • Veröffentlicht 11.06.2025 16:26:25
  • Zuletzt bearbeitet 12.06.2025 16:06:20

A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into th...

  • EPSS 0.02%
  • Veröffentlicht 21.04.2025 07:16:45
  • Zuletzt bearbeitet 28.05.2025 15:49:49

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 26.04.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:10

An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser wi...

  • EPSS 0.23%
  • Veröffentlicht 06.02.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 02:29:29

Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, la...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 28.12.2009 19:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a shop.product_details shop.flypage action.

  • EPSS 0.14%
  • Veröffentlicht 11.09.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site request forgery (CSRF) vulnerability in VirtueMart 1.0.13a and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • EPSS 0.39%
  • Veröffentlicht 11.09.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and earlier allows remote attackers to read arbitrary files via vectors related to a template file.

  • EPSS 0.59%
  • Veröffentlicht 18.10.2007 20:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in VirtueMart before 1.0.13 allows remote attackers to execute arbitrary PHP code via unspecified vectors.