Aggregates CVE and security vulnerability intelligence across all hikashop-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk sql injection and vendor risk cross-site scripting, with potential vendor impact session compromise and vendor impact data exposure across vendor surface software deployment use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-25225 | A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions. | [email protected] | 6.5 | 0.04% | 2025-03-15 | 2025-05-28 |
| CVE-2025-22210 | A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend. | [email protected] | 7.2 | 0.07% | 2025-02-25 | 2025-06-04 |
| CVE-2024-40746 | A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend. | [email protected] | 5.4 | 0.06% | 2024-10-21 | 2025-03-19 |
| CVE-2023-38044 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | [email protected] | 9.8 | 0.07% | 2023-08-07 | 2024-11-21 |
| CVE-2015-7344 | HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption]. | [email protected] | 4.8 | 0.24% | 2020-03-09 | 2024-11-21 |