cs-cart CVE Vulnerabilities & CVE List (24)

Products (CPE): — CVEs: 24

cs-cart vulnerability overview

Aggregates CVE and security vulnerability intelligence across all cs-cart-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting, vendor risk sql injection, vendor risk csrf, and vendor risk path handling and related problems; some flaws may lead to vendor impact session compromise.

Vulnerability distribution trend (last 24 months)

Showing 120 of 24 CVEs
«« First « Prev Page 1 / 2 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-50850 An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks. [email protected] 8.6 0.35% 2025-07-31 2025-08-06
CVE-2025-50848 A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious content, such as a fake login form for credential harvesting or scripts for Cross-Site Scripting (XSS) attacks. Since the content is served from a trusted domain, it significantly increases the likelihood [email protected] 6.1 0.18% 2025-07-31 2025-08-06
CVE-2025-50847 Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request. [email protected] 6.5 0.27% 2025-07-31 2025-08-06
CVE-2023-26691 Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on. [email protected] 7.2 0.77% 2024-09-25 2025-04-24
CVE-2023-26690 File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu. [email protected] 8.8 0.68% 2024-09-25 2025-04-24
CVE-2023-26689 An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request. [email protected] 9.8 0.19% 2024-09-25 2025-04-24
CVE-2023-26688 Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface. [email protected] 5.4 0.07% 2024-09-25 2025-04-24
CVE-2023-26687 Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on. [email protected] 8.8 0.94% 2024-09-25 2025-04-24
CVE-2023-26686 File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop. [email protected] 9.8 0.68% 2024-09-25 2025-04-24
CVE-2021-32202 In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page. [email protected] 6.1 0.24% 2021-09-14 2024-11-21
CVE-2017-15673 The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page. [email protected] 7.2 0.38% 2017-11-28 2026-05-13
CVE-2017-10886 Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors. [email protected] 5.4 0.25% 2017-11-17 2026-05-13
CVE-2017-2138 Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors. [email protected] 8.8 0.14% 2017-08-02 2026-05-13
CVE-2016-4862 Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers. [email protected] 8.8 2.43% 2017-04-20 2026-05-13
CVE-2015-2701 Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/. [email protected] 6.8 0.69% 2015-03-25 2026-05-06
CVE-2013-7317 Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) settings_file or (2) data_file parameter to (a) ampie.swf, (b) amline.swf, or (c) amcolumn.swf. [email protected] 4.3 0.59% 2014-01-24 2026-04-29
CVE-2013-0118 CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self. [email protected] 5.0 0.33% 2013-02-24 2026-04-29
CVE-2009-4891 SQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a products.view action. [email protected] 7.5 0.53% 2010-06-11 2026-04-29
CVE-2009-2579 SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2. [email protected] 6.5 0.29% 2009-08-05 2026-04-23
CVE-2008-6394 SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter. [email protected] 7.5 0.90% 2009-03-04 2026-04-23
«« First « Prev Page 1 / 2 Next »
cvelogic Threat Intelligence