Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Virtuemart

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 17
30.5
VTI Score
Low

Virtuemart is a focused e-commerce extension for the Joomla content-management system, positioned prominently within the open-source CMS ecosystem despite a narrow product portfolio. Its vulnerability profile centers on web-application input handling, with recurrent weaknesses including SQL injection, cross-site scripting, cross-site request forgery, and improper input validation characteristic of server-side PHP components, while public exploit code frequently becomes available for disclosed flaws. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Virtuemart over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Jun 11, 2025
408 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7465MEDIUM
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the produ
Apr 26, 20185.429NOYES
CVE-2009-4430HIGH
SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a shop.product_details shop.fly
Dec 28, 20097.528NOYES
CVE-2006-5096MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow r
Sep 29, 20066.827NOYES
CVE-2016-10379HIGH
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmet
May 29, 20177.224NONO
CVE-2005-4829HIGH
VirtueMart before 1.0.1 does not properly handle errors when a user is forbidden to read a requested page, which has unknown impact and remote attack vectors.
Dec 31, 200510.024NONO
CVE-2025-6001HIGH
A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a
Jun 11, 20258.323NONO
CVE-2025-6002HIGH
An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, includi
Jun 11, 20257.221NONO
CVE-2007-5563HIGH
Unspecified vulnerability in VirtueMart before 1.0.13 allows remote attackers to execute arbitrary PHP code via unspecified vectors.
Oct 18, 20077.519NONO
CVE-2007-1096MEDIUM
Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart before 20070116 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE:
Feb 26, 20076.819NONO
CVE-2006-6945HIGH
SQL injection vulnerability in Virtuemart 1.0.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) Itemid, (2) product_id, a
Jan 19, 20077.519NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
53%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network6 (35.3%)
Unknown11 (64.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (35.3%)
High0 (0.0%)
Unknown11 (64.7%)
User Interaction
None3 (17.6%)
Unknown11 (64.7%)
Required3 (17.6%)
Privileges Required
Low2 (11.8%)
High3 (17.6%)
None1 (5.9%)
Unknown11 (64.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
17.6% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Virtuemart.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Virtuemart — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Virtuemart's Products

View all 3 CNAs →

Top CWEs