Cpcommerce Project maintains a niche e-commerce platform product affected by path-traversal vulnerabilities that enable unauthorized file access. Current severity, exploitation, and exposure details are shown in the live-statistics panel alongside this summary.
The number and severity of CVEs published that impact products developed by Cpcommerce Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1936CRITICAL _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection me | Jun 5, 2009 | 9.8 | 64 | NO | YES |
CVE-2008-1908HIGH Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the language paramete | Apr 22, 2008 | 7.5 | 29 | NO | YES |
CVE-2009-1345HIGH SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_document parameter. | Apr 20, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-1907HIGH Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) i | Apr 22, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-2959HIGH SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter. | May 31, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-2890HIGH SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter. | May 30, 2007 | 7.5 | 28 | NO | YES |
CVE-2008-1906MEDIUM Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a view.year ac | Apr 22, 2008 | 4.3 | 21 | NO | YES |
CVE-2003-1500MEDIUM PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter. | Dec 31, 2003 | 6.8 | 19 | NO | NO |
CVE-2008-4121MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in a searc | Oct 21, 2008 | 4.3 | 16 | NO | NO |
CVE-2007-2968MEDIUM Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full | Jun 1, 2007 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpcommerce Project.
Media articles that mention a CVE ID that affects a product developed by Cpcommerce Project — matched by CVE ID, not by vendor name.