Freewebshop is a modestly represented e-commerce platform product whose vulnerability profile centers on application-layer input handling and code generation flaws, including path traversal, code injection, cross-site scripting, and SQL injection. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and appeal of web application vulnerabilities for automated testing and deployment in attack toolkits. Defenders should treat this vendor's advisories as patching priorities where the platform is exposed to untrusted users; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freewebshop over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5846MEDIUM Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter | Nov 10, 2006 | 6.4 | 32 | NO | YES |
CVE-2007-6466HIGH Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2 | Dec 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-5772HIGH Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) prod para | Nov 6, 2006 | 7.5 | 28 | NO | YES |
CVE-2009-2338MEDIUM Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arb | Jul 7, 2009 | 6.8 | 27 | NO | YES |
CVE-2006-5773MEDIUM Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the installation path via a .. (dot dot | Nov 6, 2006 | 5.0 | 27 | NO | YES |
CVE-2011-5147MEDIUM Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and earlier allows remote attackers to injec | Aug 31, 2012 | 5.0 | 26 | NO | YES |
CVE-2007-6711HIGH Unspecified vulnerability in customer.php in FreeWebshop.org 2.2.5, 2.2.6 and 2.2.7WIP1/2 allows remote attackers to gain administrator privileges via unknown vectors. | Mar 24, 2008 | 10.0 | 25 | NO | NO |
CVE-2006-5847MEDIUM Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | Nov 10, 2006 | 6.1 | 25 | NO | YES |
CVE-2006-6941MEDIUM index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path in | Jan 19, 2007 | 5.0 | 23 | NO | YES |
CVE-2007-0531HIGH PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the | Jan 26, 2007 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freewebshop.
Media articles that mention a CVE ID that affects a product developed by Freewebshop — matched by CVE ID, not by vendor name.