alegrocart CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

alegrocart vulnerability overview

Aggregates CVE and security vulnerability intelligence across all alegrocart-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection, vendor risk csrf, and vendor risk path handling and related problems; some flaws may lead to vendor impact file overwrite and vendor impact data exposure.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2015-9227 PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2. [email protected] 7.2 2.46% 2017-09-11 2026-05-13
CVE-2015-9226 Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote authenticated users with a valid Paypal transaction token to execute arbitrary SQL commands via the ref parameter in the (3) orderUpdate function in upload/catalog/extension/payment/paypal.php. [email protected] 7.2 1.98% 2017-09-11 2026-05-13
CVE-2011-3701 AlegroCart 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by common.php and certain other files. [email protected] 5.0 1.33% 2011-09-23 2026-04-29
CVE-2010-1611 Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication of the administrator for requests that reset the administrator password via a POST to admin/ with an update action. [email protected] 6.8 1.02% 2010-04-29 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence