CVE detail
CVE-2019-13026
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- Hacking eCommerce sites based on OXID eShop by chaining 2 flawsSecurity Affairs
Researchers at RIPS Technologies discovered vulnerabilities in the OXID eShop platform that could expose eCommerce websites to hack. Experts at RIPS Technologies discovered several flaws in the OXID eShop platform that could be exploited by unauthenticated attackers to compromise eCommerce websites. OXID eShop is a popular e-commerce software platform used by important brands like Mercedes […]
newssecurityaffairs.comJul 31, 2019, 6:51 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2018-20715CVSS 9.8 · Critical
The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.ph…
- CVE-2026-65532CVSS 7.6 · High
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
- CVE-2026-65526CVSS 8.5 · High
Contributor SQL Injection in Visualizer <= 4.0.6 versions.
- CVE-2026-65494CVSS 7.1 · High
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
- CVE-2026-65462CVSS 7.6 · High
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
- CVE-2026-65454CVSS 8.5 · High
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.