Qualiteam's vulnerability footprint centers on X-Cart, a widely deployed e-commerce platform, where disclosures cluster around web-application input-handling weaknesses including cross-site scripting, code injection, and improper input validation. The vendor's vulnerabilities tend toward a meaningful share of serious outcomes and have an elevated tendency to acquire public exploit code, reflecting the appeal of e-commerce platforms as attack targets and the web-tier code-injection classes involved. Defenders should prioritize this vendor's advisories for internet-exposed storefronts and inventory downstream integrations; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qualiteam over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0241HIGH X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php. | Nov 23, 2004 | 10.0 | 44 | NO | YES |
CVE-2007-4907HIGH Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepar | Sep 17, 2007 | 7.5 | 37 | NO | YES |
CVE-2006-4904HIGH Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary P | Sep 21, 2006 | 7.5 | 32 | NO | YES |
CVE-2004-0242MEDIUM X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command. | Nov 23, 2004 | 5.0 | 30 | NO | YES |
CVE-2006-2827CRITICAL SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for patt | Jun 5, 2006 | 9.8 | 29 | NO | NO |
CVE-2005-1822HIGH Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3 | Jun 1, 2005 | 7.5 | 28 | NO | YES |
CVE-2017-15285HIGH X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before s | Oct 12, 2017 | 8.8 | 27 | NO | NO |
CVE-2012-2570MEDIUM Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the symb parameter. | Aug 15, 2012 | 4.3 | 26 | NO | YES |
CVE-2015-0951MEDIUM X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request. | Apr 5, 2015 | 6.5 | 23 | NO | NO |
CVE-2005-1823MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable paramet | Jun 1, 2005 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qualiteam.
Media articles that mention a CVE ID that affects a product developed by Qualiteam — matched by CVE ID, not by vendor name.