Gambio develops e-commerce platform software, and its vulnerability footprint concentrates on a narrow product line spanning Gambio, Gambio GX, and XT variants that serve as the backend for online retail operations. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, with recurrent weakness classes including SQL injection, unrestricted file uploads, unsafe deserialization, and cross-site scripting that reflect the input-handling and session-management demands of web-facing commerce applications. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gambio over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23759CRITICAL Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function. | Feb 12, 2024 | 9.8 | 64 | NO | YES |
CVE-2010-4954HIGH SQL injection vulnerability in product_reviews_info.php in xt:Commerce Gambio 2008 allows remote attackers to execute arbitrary SQL commands via the products_id parameter. | Oct 9, 2011 | 7.5 | 30 | NO | YES |
CVE-2020-10984HIGH Gambio GX before 4.0.1.0 allows admin/admin.php CSRF. | Jul 28, 2020 | 8.8 | 28 | NO | NO |
CVE-2024-23763CRITICAL SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter. | Feb 12, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-23761CRITICAL Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template. | Feb 12, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-23762HIGH Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file. | Feb 12, 2024 | 7.8 | 22 | NO | NO |
CVE-2020-10985MEDIUM Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php. | Jul 28, 2020 | 4.8 | 15 | NO | NO |
CVE-2020-10983MEDIUM Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php. | Jul 28, 2020 | 4.9 | 15 | NO | NO |
CVE-2020-10982MEDIUM Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php. | Jul 28, 2020 | 4.9 | 15 | NO | NO |
Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the | Feb 12, 2024 | 2.7 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gambio.
Media articles that mention a CVE ID that affects a product developed by Gambio — matched by CVE ID, not by vendor name.