Virtuemart is a focused e-commerce extension for the Joomla content-management system, positioned prominently within the open-source CMS ecosystem despite a narrow product portfolio. Its vulnerability profile centers on web-application input handling, with recurrent weaknesses including SQL injection, cross-site scripting, cross-site request forgery, and improper input validation characteristic of server-side PHP components, while public exploit code frequently becomes available for disclosed flaws. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Virtuemart over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7465MEDIUM An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the produ | Apr 26, 2018 | 5.4 | 29 | NO | YES |
CVE-2009-4430HIGH SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a shop.product_details shop.fly | Dec 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2006-5096MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow r | Sep 29, 2006 | 6.8 | 27 | NO | YES |
CVE-2016-10379HIGH The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmet | May 29, 2017 | 7.2 | 24 | NO | NO |
CVE-2005-4829HIGH VirtueMart before 1.0.1 does not properly handle errors when a user is forbidden to read a requested page, which has unknown impact and remote attack vectors. | Dec 31, 2005 | 10.0 | 24 | NO | NO |
CVE-2025-6001HIGH A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a | Jun 11, 2025 | 8.3 | 23 | NO | NO |
CVE-2025-6002HIGH An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, includi | Jun 11, 2025 | 7.2 | 21 | NO | NO |
CVE-2007-5563HIGH Unspecified vulnerability in VirtueMart before 1.0.13 allows remote attackers to execute arbitrary PHP code via unspecified vectors. | Oct 18, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-1096MEDIUM Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart before 20070116 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: | Feb 26, 2007 | 6.8 | 19 | NO | NO |
CVE-2006-6945HIGH SQL injection vulnerability in Virtuemart 1.0.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) Itemid, (2) product_id, a | Jan 19, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virtuemart.
Media articles that mention a CVE ID that affects a product developed by Virtuemart — matched by CVE ID, not by vendor name.