Samedia's vulnerability footprint centers on its Landshop e-commerce platform, where disclosures cluster around application-layer input-handling and request-forgery weaknesses including cross-site scripting, SQL injection, and cross-site request forgery. This is a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Samedia over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5900HIGH Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/ac | Nov 17, 2012 | 7.5 | 31 | NO | YES |
CVE-2012-5898MEDIUM Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authentication of administrators for requests that change account se | Nov 17, 2012 | 6.8 | 29 | NO | YES |
CVE-2006-5914HIGH SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via the infield parameter. NOTE: the start, search_order, searc | Nov 15, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-5915MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) k | Nov 15, 2006 | 6.8 | 27 | NO | YES |
CVE-2012-5899MEDIUM Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] pa | Nov 17, 2012 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Samedia.
Media articles that mention a CVE ID that affects a product developed by Samedia — matched by CVE ID, not by vendor name.