phpshop CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

phpshop vulnerability overview

Aggregates CVE and security vulnerability intelligence across all phpshop-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection and vendor risk csrf and related problems; some flaws may lead to vendor impact data exposure, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2011-1069 PHPShop through 0.8.1 has XSS. [email protected] 6.1 0.18% 2020-02-05 2024-11-21
CVE-2010-4836 Cross-site scripting (XSS) vulnerability in register.html in PHPShop 2.1 EE and earlier allows remote attackers to inject arbitrary web script or HTML via the name_new parameter. [email protected] 4.3 0.61% 2011-09-14 2026-04-29
CVE-2009-4572 Cross-site request forgery (CSRF) vulnerability in PhpShop 0.8.1 allows remote attackers to hijack the authentication of arbitrary users for requests that invoke the cartAdd function in a shop/cart action to the default URI. [email protected] 6.8 0.15% 2010-01-05 2026-04-23
CVE-2009-4571 Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id parameter in an admin/function_list action, the (2) vendor_id parameter in a vendor/vendor_form action, the (3) module_id parameter in an admin/module_form action, the (4) user_id parameter in an admin/user_form action, the (5) vendor_category_id parameter in a vendor/vendor_category_form action, the (6) user_id parameter in a store/user_form action, [email protected] 7.5 0.19% 2010-01-05 2026-04-23
CVE-2009-4570 Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI. [email protected] 4.3 0.34% 2010-01-05 2026-04-23
CVE-2008-0681 SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as demonstrated by a shop/flypage action. [email protected] 6.8 0.33% 2008-02-12 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence