CVE-2025-7567
- EPSS 0.03%
- Veröffentlicht 14.07.2025 03:14:05
- Zuletzt bearbeitet 15.07.2025 13:14:24
A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processing of the file header.html. The manipulation of the argument lang/system_type leads to cross site scripting. The attack may be init...
CVE-2025-5108
- EPSS 0.1%
- Veröffentlicht 23.05.2025 12:31:05
- Zuletzt bearbeitet 02.07.2025 00:49:48
A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/controller/Payment.php of the component ZIP File Handler. The manipulation of the argument params leads t...
CVE-2025-28094
- EPSS 0.16%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:09:44
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
CVE-2025-28093
- EPSS 0.27%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:11:25
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
CVE-2025-28092
- EPSS 0.27%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:12:53
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
CVE-2025-26325
- EPSS 0.39%
- Veröffentlicht 27.02.2025 22:15:39
- Zuletzt bearbeitet 10.04.2025 17:28:00
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
CVE-2025-1611
- EPSS 0.04%
- Veröffentlicht 24.02.2025 02:15:32
- Zuletzt bearbeitet 02.07.2025 17:41:27
A vulnerability was found in ShopXO up to 6.4.0. It has been classified as problematic. This affects an unknown part of the file app/service/ThemeAdminService.php of the component Template Handler. The manipulation leads to injection. It is possible ...
CVE-2024-44682
- EPSS 0.17%
- Veröffentlicht 30.08.2024 22:15:06
- Zuletzt bearbeitet 14.03.2025 16:15:35
ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.
CVE-2024-6524
- EPSS 0.11%
- Veröffentlicht 05.07.2024 12:15:02
- Zuletzt bearbeitet 21.11.2024 09:49:48
A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. The manipulation of the argument source leads to server-side request f...
CVE-2021-41938
- EPSS 0.38%
- Veröffentlicht 19.05.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:58
An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.