Skip to main content

Vendor/product archive

oxid-esales / eshop CVEs

Beta · best-effort

13 CVEs tagged to oxid-esales / eshop2 Critical, 5 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-56526

Published May 13, 2025

An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38330

Published Aug 2, 2023

OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified hea…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17062

Published Nov 5, 2019

An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.1…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13026

Published Jul 30, 2019

OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, custom…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-20715

Published Jan 15, 2019

The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.ph…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12579

Published Aug 20, 2018

An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3,…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14993

Published Feb 20, 2018

OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12415

Published Feb 20, 2018

OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5763

Published Feb 19, 2018

An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a s…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6926

Published Jan 19, 2018

The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4919

Published Jan 19, 2018

OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2016

Published Mar 25, 2014

Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5913

Published Oct 15, 2013

Cross-site scripting (XSS) vulnerability in the getRecommSearch function in recommlist.php in OXID eShop before 4.6.7, Professional and Community Edition 4.7.x before 4.7.8, and E…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1