Rakhisoftware's vulnerability profile centers on its shopping-cart product, with disclosed issues recurring across application-layer input-handling and data-protection weaknesses including cross-site scripting, SQL injection, and exposure of sensitive information. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rakhisoftware over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6279HIGH RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation pa | Feb 25, 2009 | 7.8 | 29 | NO | YES |
CVE-2008-6277HIGH SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategor | Feb 25, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6278MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web scrip | Feb 25, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rakhisoftware.
Media articles that mention a CVE ID that affects a product developed by Rakhisoftware — matched by CVE ID, not by vendor name.