The Ecommerce Codeigniter Bootstrap Project is a focused web application framework-based e-commerce platform whose vulnerability profile centers on a single product line. The recurring exposure clusters around cross-site scripting weaknesses inherent to web template rendering, reflecting the input-handling demands of a customer-facing commerce application. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecommerce Codeigniter Bootstrap Project over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31820CRITICAL An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit metho | Apr 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-31822CRITICAL An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method o | Apr 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-31823HIGH An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage metho | Apr 29, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-31821HIGH SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQ | Apr 29, 2024 | 8.0 | 22 | NO | NO |
CVE-2022-26624MEDIUM Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php. | Apr 8, 2022 | 6.1 | 22 | NO | NO |
CVE-2023-23010MEDIUM Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbi | Jan 20, 2023 | 6.1 | 21 | NO | NO |
CVE-2022-35213MEDIUM Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php. | Aug 18, 2022 | 6.1 | 21 | NO | NO |
CVE-2020-25090MEDIUM Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php. | Sep 3, 2020 | 6.1 | 21 | NO | NO |
CVE-2020-25088MEDIUM Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. | Sep 3, 2020 | 6.1 | 21 | NO | NO |
CVE-2020-25093MEDIUM Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views | Sep 3, 2020 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecommerce Codeigniter Bootstrap Project.
Media articles that mention a CVE ID that affects a product developed by Ecommerce Codeigniter Bootstrap Project — matched by CVE ID, not by vendor name.