Skip to main content

Vendor/product archive

welcart / welcart_e-commerce CVEs

Beta · best-effort

36 CVEs tagged to welcart / welcart_e-commerce1 Critical, 13 High, 22 Medium, 0 Low, 0 Unrated.

CVE-2022-3946

Published Dec 12, 2022

The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping meth…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3935

Published Dec 12, 2022

The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Stored…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20734

Published Jun 22, 2021

Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28339

Published Nov 7, 2020

The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4828

Published Jun 25, 2016

The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to obtain access by leveraging knowledge of the e-mail address a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4827

Published Jun 25, 2016

Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unsp…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4826

Published Jun 25, 2016

Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unsp…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4825

Published Jun 25, 2016

The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serializ…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7791

Published Dec 29, 2015

Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2973

Published Jul 24, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the Welcart plugin before 1.4.18 for WordPress allow remote attackers to inject arbitrary web script or HTML via the usces_r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-36 of 36 CVEsPage 2 of 2