shopwind CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

shopwind vulnerability overview

Aggregates CVE and security vulnerability intelligence across all shopwind-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting, vendor risk path handling, and vendor risk sql injection; exposure may include vendor impact session compromise in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-1705 A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php of the component Installation. The manipulation leads to code injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-254393 was assigned to this vulner [email protected] 5.6 0.09% 2024-02-21 2025-02-12
CVE-2022-43321 Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php. [email protected] 6.1 0.32% 2022-11-09 2025-05-01
CVE-2022-30453 ShopWind <= 3.4.2 has a RCE vulnerability in Database.php [email protected] 9.8 0.60% 2022-05-11 2024-11-21
CVE-2022-30452 ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php [email protected] 7.2 0.30% 2022-05-11 2024-11-21
CVE-2022-30059 Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php. [email protected] 6.5 0.44% 2022-05-11 2024-11-21
CVE-2022-30058 Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.php. [email protected] 5.3 0.25% 2022-05-11 2024-11-21
CVE-2022-30057 Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability. [email protected] 5.4 0.19% 2022-05-11 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence