Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
112025.8%CRITICAL

Related CVEs

12
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-5108A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/controller/Payment.php of the component ZIP File Handler. The manipulation of the argument params leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.MEDIUM5.326.3%May 23, 2025
CVE-2025-28094shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.MEDIUM6.59.7%Mar 28, 2025
CVE-2025-28093ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.MEDIUM6.315.9%Mar 28, 2025
CVE-2025-28092ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.MEDIUM6.315.9%Mar 28, 2025
CVE-2025-26325ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.CRITICAL9.835.5%Feb 27, 2025
CVE-2025-1611A vulnerability was found in ShopXO up to 6.4.0. It has been classified as problematic. This affects an unknown part of the file app/service/ThemeAdminService.php of the component Template Handler. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.MEDIUM5.140.6%Feb 24, 2025
CVE-2024-44682ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.MEDIUM6.124.1%Aug 30, 2024
CVE-2024-6524A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. The manipulation of the argument source leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270367. NOTE: The original disclosure confuses CSRF with SSRF.MEDIUM5.338.0%Jul 5, 2024
CVE-2021-41938An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.HIGH7.2May 19, 2022
CVE-2022-28056ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.CRITICAL9.8May 2, 2022
CVE-2020-26008The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via uploading a crafted PHP file.HIGH7.8Mar 20, 2022
CVE-2020-26007An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.HIGH7.8Mar 20, 2022