Skip to main content

Vendor archive

tp-shop CVEs

Beta · best-effort

3 CVEs tagged to vendor tp-shop3 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2020-18164

Published Aug 17, 2021

SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-9919

Published May 2, 2018

A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtain sensitive information, attack intranet hosts, or pos…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16614

Published Mar 30, 2018

SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command exe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1