Vulnerabilities (CVE)

Filtered by vendor Cs-cart Subscribe
Total 24 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-50847 1 Cs-cart 1 Cs-cart 2025-08-06 N/A N/A
Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request.
CVE-2025-50848 1 Cs-cart 1 Cs-cart 2025-08-06 N/A N/A
A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious content, such as a fake login form for credential harvesting or scripts for Cross-Site Scripting (XSS) attacks. Since the content is served from a trusted domain, it significantly increases the likelihood of successful phishing or script execution against other users.
CVE-2025-50850 1 Cs-cart 1 Cs-cart 2025-08-06 N/A N/A
An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks.
CVE-2023-26686 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 N/A N/A
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.
CVE-2023-26687 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 N/A N/A
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.
CVE-2023-26689 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 N/A N/A
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
CVE-2023-26691 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 N/A N/A
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.
CVE-2023-26690 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 N/A N/A
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.
CVE-2023-26688 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 N/A N/A
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.
CVE-2007-0230 1 Cs-cart 1 Cs-cart 2024-08-07 7.5 HIGH N/A
PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter. NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use
CVE-2017-2138 1 Cs-cart 2 Cs-cart, Cs-cart Multivendor 2023-01-10 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2021-32202 1 Cs-cart 1 Cs-cart 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page.
CVE-2008-6394 1 Cs-cart 1 Cs-cart 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.
CVE-2008-1458 1 Cs-cart 1 Cs-cart 2018-10-11 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action. NOTE: it was also reported that 1.3.5-SP2 trial edition is also affected.
CVE-2009-2579 1 Cs-cart 1 Cs-cart 2018-10-10 6.5 MEDIUM N/A
SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.
CVE-2017-15673 1 Cs-cart 1 Cs-cart 2017-12-20 9.0 HIGH 7.2 HIGH
The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.
CVE-2017-10886 1 Cs-cart 2 Cs-cart, Cs-cart Multivendor 2017-12-04 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2006-2863 1 Cs-cart 1 Cs-cart 2017-10-19 5.1 MEDIUM N/A
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.
CVE-2009-4891 1 Cs-cart 1 Cs-cart 2017-09-19 7.5 HIGH N/A
SQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a products.view action.
CVE-2016-4862 1 Cs-cart 1 Cs-cart 2017-04-26 6.5 MEDIUM 8.8 HIGH
Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.