VendorsOXIDforgeoxid_eshopall versions
Vulnerabilities

OXIDforge OXID eShop Enterprise Edition

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2009-3112
Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop backend via a crafted parameter.
Published 2009-09-09 · Modified
10.0EPSS 0.020
CVE-2016-5072
OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition v4.8.12, Community Edition v4.9.9.
Published 2017-04-10 · Modified
8.8EPSS 0.019
CVE-2023-26260
OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.
Published 2023-04-11 · Modified
5.4EPSS 0.004