Online Store System Project maintains a narrowly scoped e-commerce platform product that exhibits a consistent pattern of web application security gaps, particularly cross-site scripting, path traversal, and missing authentication controls on critical functions. These weakness classes are characteristic of input-validation and access-control shortfalls in web-facing transaction systems; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Online Store System Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-8291HIGH Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal. | Oct 1, 2019 | 7.5 | 19 | NO | NO |
CVE-2019-8290MEDIUM Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special charact | Oct 1, 2019 | 6.1 | 17 | NO | NO |
CVE-2019-8292MEDIUM Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion. | Oct 1, 2019 | 5.3 | 16 | NO | NO |
CVE-2019-8289MEDIUM Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable | Oct 1, 2019 | 5.4 | 16 | NO | NO |
CVE-2019-8288MEDIUM Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized. | Oct 1, 2019 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Online Store System Project.
Media articles that mention a CVE ID that affects a product developed by Online Store System Project — matched by CVE ID, not by vendor name.