Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Shopizer

First CVE: Jul 15, 2014Active for: 12 yearsTotal CVEs: 14
32.5
VTI Score
Medium

Shopizer is a focused open-source e-commerce platform whose vulnerability profile centers on a single product serving online retailers and small-business deployments. The vendor's disclosures recur through web-application and authentication weaknesses including cross-site scripting, CSRF, authorization bypass, improper authentication, and input-validation flaws—issues typical of e-commerce applications handling user input, session management, and payment-related access control. Public exploit code frequently becomes available for vulnerabilities affecting this platform; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Shopizer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2014
12 years ago
Most Recent CVE
Aug 22, 2025
336 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-4963MEDIUM
Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.
Jul 15, 20146.832NOYES
CVE-2014-4964MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users for requests that (1) modify c
Jul 15, 20146.831NOYES
CVE-2014-4962MEDIUM
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of
Jul 15, 20146.431NOYES
CVE-2021-33562MEDIUM
A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about
May 24, 20214.828NOYES
CVE-2022-23063HIGH
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already
May 3, 20228.827NONO
CVE-2021-33561MEDIUM
A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of sto
May 24, 20214.827NOYES
CVE-2025-51605HIGH
An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whiteli
Aug 22, 20258.126NONO
CVE-2014-4965MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) customername parameter t
Jul 15, 20144.326NOYES
CVE-2022-23061MEDIUM
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Refer
May 1, 20226.523NONO
CVE-2022-23059MEDIUM
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containi
Mar 29, 20224.819NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
86%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (64.3%)
Unknown5 (35.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (57.1%)
High1 (7.1%)
Unknown5 (35.7%)
User Interaction
None4 (28.6%)
Unknown5 (35.7%)
Required5 (35.7%)
Privileges Required
Low3 (21.4%)
High5 (35.7%)
None1 (7.1%)
Unknown5 (35.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
42.9% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Shopizer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Shopizer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Shopizer's Products

View all 3 CNAs →

Top CWEs