Php Multivendor Ecommerce

Vendor:

First CVE: Dec 13, 2017 · Active for 8 years

11
Total CVEs
More Total CVEs than 90% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Php Multivendor Ecommerce over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2017
8 years ago
Most Recent CVE
Dec 28, 2017
3,134 days ago

CVE Severity & Scoring

Php Multivendor Ecommerce11 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (45.5%)
Unknown0 (0.0%)
Required6 (54.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
Dec 13, 20179.841NOYES
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.
Dec 28, 20179.828NONO
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.
Dec 28, 20179.828NONO
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.
Dec 28, 20179.828NONO
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
Dec 28, 20178.826NONO
PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
Dec 28, 20178.625NONO
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.
Dec 28, 20176.120NONO
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.
Dec 28, 20176.120NONO
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.
Dec 28, 20176.120NONO
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.
Dec 28, 20176.120NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Php Multivendor Ecommerce

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.019.83.0%01