CVE-2026-12204
- EPSS 0.29%
- Veröffentlicht 15.06.2026 01:15:07
- Zuletzt bearbeitet 15.06.2026 20:42:32
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of the component Scheduled Task Endpoint. Executing a ...
- EPSS 0.32%
- Veröffentlicht 14.07.2025 03:14:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processing of the file header.html. The manipulation of the argument lang/system_type leads to cross site scripting. The attack may be init...
CVE-2025-5108
- EPSS 0.34%
- Veröffentlicht 23.05.2025 12:31:05
- Zuletzt bearbeitet 02.07.2025 00:49:48
A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/controller/Payment.php of the component ZIP File Handler. The manipulation of the argument params leads t...
CVE-2025-28094
- EPSS 0.2%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:09:44
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
CVE-2025-28093
- EPSS 0.25%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:11:25
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
CVE-2025-28092
- EPSS 0.25%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:12:53
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
CVE-2025-26325
- EPSS 0.45%
- Veröffentlicht 27.02.2025 22:15:39
- Zuletzt bearbeitet 10.04.2025 17:28:00
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
CVE-2025-1611
- EPSS 0.53%
- Veröffentlicht 24.02.2025 02:15:32
- Zuletzt bearbeitet 02.07.2025 17:41:27
A vulnerability was found in ShopXO up to 6.4.0. It has been classified as problematic. This affects an unknown part of the file app/service/ThemeAdminService.php of the component Template Handler. The manipulation leads to injection. It is possible ...
CVE-2024-44682
- EPSS 0.32%
- Veröffentlicht 30.08.2024 22:15:06
- Zuletzt bearbeitet 14.03.2025 16:15:35
ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.
CVE-2024-6524
- EPSS 0.48%
- Veröffentlicht 05.07.2024 12:15:02
- Zuletzt bearbeitet 21.11.2024 09:49:48
A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. The manipulation of the argument source leads to server-side request f...