Oxidforge develops the OXID eShop e-commerce platform, which serves as the core product in its narrow vendor footprint. The durable signal clusters around application-layer weaknesses including code injection, CRLF injection, and session-fixation issues that arise from web input handling and session management in a publicly exposed storefront application; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oxidforge over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2017MEDIUM CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition | Jan 18, 2018 | 6.1 | 32 | NO | YES |
CVE-2016-5072HIGH OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterpr | Apr 10, 2017 | 8.8 | 27 | NO | NO |
CVE-2009-3112HIGH Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop ba | Sep 9, 2009 | 10.0 | 25 | NO | NO |
CVE-2023-26260MEDIUM OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the use | Apr 11, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oxidforge.
Media articles that mention a CVE ID that affects a product developed by Oxidforge — matched by CVE ID, not by vendor name.