Vulnerabilities (CVE)

Filtered by vendor Shopwind Subscribe
Filtered by product Shopwind
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-30059 1 Shopwind 1 Shopwind 2022-05-20 5.5 MEDIUM 6.5 MEDIUM
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php.
CVE-2022-30058 1 Shopwind 1 Shopwind 2022-05-20 5.0 MEDIUM 5.3 MEDIUM
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.php.
CVE-2022-30057 1 Shopwind 1 Shopwind 2022-05-20 3.5 LOW 5.4 MEDIUM
Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.