Cosmicphp maintains Cosmic Shopping Cart, a modestly represented e-commerce platform whose vulnerability profile centers on web application input-handling weaknesses, particularly cross-site scripting in page-generation contexts. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cosmicphp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2650HIGH SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter. | May 30, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-2649MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicS | May 30, 2006 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cosmicphp.
Media articles that mention a CVE ID that affects a product developed by Cosmicphp — matched by CVE ID, not by vendor name.