Vulnerabilities (CVE)

Filtered by vendor Cs-cart Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15673 1 Cs-cart 1 Cs-cart 2017-12-20 9.0 HIGH 7.2 HIGH
The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.
CVE-2017-2138 1 Cs-cart 2 Cs-cart., Cs-cart Multivendor 2017-08-08 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2016-4862 1 Cs-cart 1 Cs-cart 2017-04-26 6.5 MEDIUM 8.8 HIGH
Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.