VendorsEcommerce-CodeIgniter-Bootstrap Projectecommerce-codeigniter-bootstrapany version
Vulnerabilities

Ecommerce-CodeIgniter-Bootstrap Project Ecommerce-CodeIgniter-Bootstrap any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2024-31820
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.
Published 2024-04-29 · Analyzed
9.8EPSS 0.019
CVE-2024-31822
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.
Published 2024-04-29 · Analyzed
9.8EPSS 0.019
CVE-2024-31821
SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.
Published 2024-04-29 · Analyzed
8.0EPSS 0.011
CVE-2021-40975
Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.
Published 2021-10-01 · Modified
6.1EPSS 0.008
CVE-2020-25086
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
Published 2020-09-03 · Modified
6.1EPSS 0.007
CVE-2020-25087
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
Published 2020-09-03 · Modified
6.1EPSS 0.007
CVE-2020-25088
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
Published 2020-09-03 · Modified
6.1EPSS 0.007
CVE-2020-25089
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
Published 2020-09-03 · Modified
6.1EPSS 0.007
CVE-2020-25090
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
Published 2020-09-03 · Modified
6.1EPSS 0.007
CVE-2020-25091
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
Published 2020-09-03 · Modified
6.1EPSS 0.007
CVE-2020-25092
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel.
Published 2020-09-03 · Modified
6.1EPSS 0.007
CVE-2020-25093
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
Published 2020-09-03 · Modified
6.1EPSS 0.007
CVE-2023-23010
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.
Published 2023-01-20 · Modified
6.1EPSS 0.006
CVE-2022-35213
Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php.
Published 2022-08-18 · Modified
6.1EPSS 0.006
CVE-2024-6526
CodeIgniter Ecommerce-CodeIgniter-Bootstrap cross site scripting
Published 2024-07-05 · Modified
6.1EPSS 0.005