VendorseShop Projecteshopany version
Vulnerabilities

eShop Project eShop any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2013-10008
sheilazpy eShop sql injection
Published 2023-01-06 · Modified
9.8EPSS 0.006
CVE-2015-9413
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
Published 2019-09-25 · Modified
6.5EPSS 0.011
CVE-2015-3421
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.
Published 2017-07-21 · Modified
6.1EPSS 0.013