Oscommerce is a narrowly scoped open-source e-commerce platform and associated shopping-cart modules that, despite a limited product portfolio, maintains prominent presence in the small-business and self-hosted retail marketplace. The vendor's vulnerability footprint is characterized by web-application attack surface: the recurring disclosures center on input-handling weaknesses including cross-site scripting, SQL injection, and improper input validation that are endemic to server-side e-commerce codebases and user-facing form processing. Public exploit code has frequently been developed for this vendor's vulnerabilities, reflecting the accessibility and appeal of e-commerce platforms to opportunistic attackers. Defenders operating or supporting Oscommerce deployments should prioritize patching cycles and treat input-validation and authentication advisories as high-priority given the sensitive payment and customer data these systems handle. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oscommerce over time
Signals from CVEs in this vendor scope (93 CVEs).
93 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2044HIGH PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP f | Jun 1, 2004 | 7.5 | 39 | NO | YES |
CVE-2023-6579CRITICAL A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart o | Dec 7, 2023 | 9.8 | 38 | NO | NO |
CVE-2002-2019HIGH PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file p | Dec 31, 2002 | 7.5 | 36 | NO | YES |
CVE-2020-27976CRITICAL osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail | Oct 28, 2020 | 9.8 | 33 | NO | NO |
CVE-2004-2021MEDIUM Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument. | Dec 31, 2004 | 5.0 | 31 | NO | YES |
CVE-2002-1991HIGH PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php. | Dec 31, 2002 | 7.5 | 31 | NO | YES |
CVE-2014-10033MEDIUM SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arb | Jan 13, 2015 | 6.5 | 30 | NO | YES |
CVE-2008-0719HIGH SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrar | Feb 12, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-4765HIGH SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results ope | Oct 28, 2008 | 7.5 | 28 | NO | YES |
CVE-2019-25497HIGH osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the currency parameter. | Feb 27, 2026 | 8.2 | 27 | NO | NO |
Signals from CVEs in this vendor scope (93 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oscommerce.
Media articles that mention a CVE ID that affects a product developed by Oscommerce — matched by CVE ID, not by vendor name.