abantecart CVE Vulnerabilities & CVE List (11)

Products (CPE): — CVEs: 11

abantecart vulnerability overview

Aggregates CVE and security vulnerability intelligence across all abantecart-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting, vendor risk sql injection, and vendor risk path handling, with potential vendor impact session compromise across vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 111 of 11 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-50972 SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index.php. Three techniques have been demonstrated: error-based injection using a crafted FLOOR-based payload, time-based blind injection via SLEEP(), and UNION-based injection to extract arbitrary data. [email protected] 9.8 0.36% 2025-08-27 2025-09-08
CVE-2025-50971 Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php. [email protected] 7.5 1.29% 2025-08-26 2025-09-04
CVE-2025-40627 Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user, through "/eyes? [XSS_PAYLOAD]". [email protected] 5.1 0.17% 2025-05-12 2025-10-10
CVE-2025-40626 Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user, through "/about_us?[XSS_PAYLOAD]". [email protected] 5.1 0.17% 2025-05-12 2025-10-10
CVE-2024-50802 A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter. [email protected] 6.0 0.06% 2024-10-31 2025-09-04
CVE-2024-50801 A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter. [email protected] 6.0 0.06% 2024-10-31 2025-09-04
CVE-2022-26521 Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type). [email protected] 7.2 7.84% 2022-03-10 2024-11-21
CVE-2021-42051 An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload. [email protected] 5.4 0.18% 2021-12-14 2024-11-21
CVE-2021-42050 An issue was discovered in AbanteCart before 1.3.2. It allows DOM Based XSS. [email protected] 6.1 0.30% 2021-12-14 2024-11-21
CVE-2016-10755 AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php. [email protected] 8.8 0.23% 2019-05-24 2024-11-21
CVE-2018-20141 AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring. [email protected] 6.1 0.35% 2019-03-21 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence