Vulnerabilities (CVE)

Filtered by vendor Zen-cart Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6578 1 Zen-cart 1 Zen Cart 2021-03-25 4.3 MEDIUM 6.1 MEDIUM
Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.
CVE-2017-10667 1 Zen-cart 1 Zen Cart 2017-07-03 4.3 MEDIUM 6.1 MEDIUM
In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.
CVE-2017-8833 1 Zen-cart 1 Zen Cart 2017-05-30 4.3 MEDIUM 6.1 MEDIUM
Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github."