Shopizer is a focused open-source e-commerce platform whose vulnerability profile centers on a single product serving online retailers and small-business deployments. The vendor's disclosures recur through web-application and authentication weaknesses including cross-site scripting, CSRF, authorization bypass, improper authentication, and input-validation flaws—issues typical of e-commerce applications handling user input, session management, and payment-related access control. Public exploit code frequently becomes available for vulnerabilities affecting this platform; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shopizer over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4963MEDIUM Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action. | Jul 15, 2014 | 6.8 | 32 | NO | YES |
CVE-2014-4964MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users for requests that (1) modify c | Jul 15, 2014 | 6.8 | 31 | NO | YES |
CVE-2014-4962MEDIUM Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of | Jul 15, 2014 | 6.4 | 31 | NO | YES |
CVE-2021-33562MEDIUM A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about | May 24, 2021 | 4.8 | 28 | NO | YES |
CVE-2022-23063HIGH In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already | May 3, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-33561MEDIUM A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of sto | May 24, 2021 | 4.8 | 27 | NO | YES |
CVE-2025-51605HIGH An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whiteli | Aug 22, 2025 | 8.1 | 26 | NO | NO |
CVE-2014-4965MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) customername parameter t | Jul 15, 2014 | 4.3 | 26 | NO | YES |
CVE-2022-23061MEDIUM In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Refer | May 1, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-23059MEDIUM A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containi | Mar 29, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shopizer.
Media articles that mention a CVE ID that affects a product developed by Shopizer — matched by CVE ID, not by vendor name.