Vpasp develops a shopping cart application for web storefronts, where its disclosed vulnerabilities cluster around web application input-handling and access-control issues spanning path traversal, cross-site scripting, and SQL injection. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vpasp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5929MEDIUM VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database containing the pa | Jan 21, 2009 | 5.0 | 23 | NO | YES |
CVE-2010-1588HIGH SQL injection vulnerability in the Getwebsess function in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arb | Apr 28, 2010 | 7.5 | 21 | NO | NO |
CVE-2007-2790MEDIUM Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via t | May 22, 2007 | 6.8 | 18 | NO | NO |
CVE-2010-1589MEDIUM Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of | Apr 28, 2010 | 5.0 | 15 | NO | NO |
CVE-2010-1590MEDIUM Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web | Apr 28, 2010 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vpasp.
Media articles that mention a CVE ID that affects a product developed by Vpasp — matched by CVE ID, not by vendor name.