Ecommerce Codeigniter Bootstrap
Vendor:
First CVE: Sep 3, 2020 · Active for 5 years
17
Total CVEs
More Total CVEs than 93% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ecommerce Codeigniter Bootstrap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2020
5 years ago
Most Recent CVE
Jul 5, 2024
749 days ago
CVE Severity & Scoring
Ecommerce Codeigniter Bootstrap17 CVEs
76%
12%
12%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (17.6%)
Unknown0 (0.0%)
Required14 (82.4%)
Privileges Required
Low2 (11.8%)
High0 (0.0%)
None15 (88.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31820CRITICAL An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit metho | Apr 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-31822CRITICAL An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method o | Apr 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-31823HIGH An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage metho | Apr 29, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-31821HIGH SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQ | Apr 29, 2024 | 8.0 | 22 | NO | NO |
CVE-2022-26624MEDIUM Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php. | Apr 8, 2022 | 6.1 | 22 | NO | NO |
CVE-2023-23010MEDIUM Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbi | Jan 20, 2023 | 6.1 | 21 | NO | NO |
CVE-2022-35213MEDIUM Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php. | Aug 18, 2022 | 6.1 | 21 | NO | NO |
CVE-2020-25090MEDIUM Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php. | Sep 3, 2020 | 6.1 | 21 | NO | NO |
CVE-2020-25088MEDIUM Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. | Sep 3, 2020 | 6.1 | 21 | NO | NO |
CVE-2020-25093MEDIUM Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views | Sep 3, 2020 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Ecommerce Codeigniter Bootstrap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2024-01-02 | 1 | 8.8 | 1.6% | 0 | 0 |