Oxid Esales maintains a focused e-commerce platform product, ESHOP, that operates as a core component in online retail deployments across Europe and elsewhere. The vendor's vulnerability profile reflects the exposure surface typical of a web-based shopping application, with disclosures spanning input handling and application-layer security concerns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oxid Esales over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2016MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise | Mar 25, 2014 | 4.3 | 33 | NO | YES |
CVE-2018-20715CRITICAL The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php | Jan 15, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-17062HIGH An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10 | Nov 5, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-13026CRITICAL OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, custome | Jul 30, 2019 | 9.8 | 26 | NO | NO |
CVE-2018-12579HIGH An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, a | Aug 20, 2018 | 8.1 | 26 | NO | NO |
CVE-2017-14993HIGH OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development) | Feb 20, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-5763MEDIUM An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a st | Feb 19, 2018 | 5.9 | 21 | NO | NO |
CVE-2017-12415HIGH OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development) | Feb 20, 2018 | 7.5 | 19 | NO | NO |
CVE-2015-6926HIGH The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication tok | Jan 19, 2018 | 7.5 | 19 | NO | NO |
CVE-2014-4919MEDIUM OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before | Jan 19, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oxid Esales.
Media articles that mention a CVE ID that affects a product developed by Oxid Esales — matched by CVE ID, not by vendor name.