Peel operates a shopping application and related product line that has surfaced a modest, recurring set of vulnerabilities centered on web application input handling and state management. The disclosures cluster around SQL injection, cross-site scripting, and cross-site request forgery—classic patterns for internet-facing applications—and a meaningful share acquire public exploit code. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Peel over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37593CRITICAL PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL c | Jul 30, 2021 | 9.1 | 41 | NO | YES |
CVE-2008-1507HIGH PEEL, possibly 3.x and earlier, has (1) a default [email protected] account with password admin, and (2) a default [email protected] account with password cinema, which allows remote atta | Mar 25, 2008 | 7.5 | 33 | NO | YES |
CVE-2012-5227HIGH SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Oct 1, 2012 | 7.5 | 31 | NO | YES |
CVE-2018-20848HIGH Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter. | Jun 30, 2019 | 8.8 | 28 | NO | NO |
CVE-2008-6892HIGH SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via the rubid parameter. NOTE: this might be the same issue as | Aug 3, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-1496HIGH Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to (a) membre.php, an | Mar 25, 2008 | 7.5 | 28 | NO | YES |
CVE-2002-2134MEDIUM haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web server that contains the code in a | Dec 31, 2002 | 5.0 | 28 | NO | YES |
CVE-2008-1495MEDIUM Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP | Mar 25, 2008 | 6.5 | 26 | NO | YES |
CVE-2012-5226MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) motclef parameter to acha | Oct 1, 2012 | 4.3 | 25 | NO | YES |
CVE-2021-41672MEDIUM PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order t | Jun 15, 2022 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Peel.
Media articles that mention a CVE ID that affects a product developed by Peel — matched by CVE ID, not by vendor name.