Vulnerabilities

Summary — last 7 days

New vulnerabilities2,861▲ 226 vs. last week
Critical / high1,331▼ 99 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
–

9 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.9)0.16%—Phpshop Php-shopAI5/29/20267/21/2026
PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that automatically submits POST requests to the users.php…
ModifiedMedium (6.1)0.69%—Phpshop2/5/20206/16/2026
PHPShop through 0.8.1 has XSS.
ModifiedMedium (4.3)1.8%💥 ExploitPhpshop9/14/20116/16/2026
Cross-site scripting (XSS) vulnerability in register.html in PHPShop 2.1 EE and earlier allows remote attackers to inject arbitrary web script or HTML via the name_new parameter.
ModifiedMedium (6.8)0.63%—Phpshop1/5/20106/16/2026
Cross-site request forgery (CSRF) vulnerability in PhpShop 0.8.1 allows remote attackers to hijack the authentication of arbitrary users for requests that invoke the cartAdd function in a shop/cart action to the default URI.
ModifiedHigh (7.5)2.0%💥 ExploitPhpshop1/5/20106/16/2026
Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id parameter in an admin/function_list action, the (2) vendor_id parameter in a vendor/vendor_form action, the (3) module_id parameter in an admin/module_form action, the (4)…
ModifiedMedium (4.3)1.1%—Phpshop1/5/20106/16/2026
Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI.
ModifiedMedium (6.8)1.2%—Edikon Phpshop3/13/20096/16/2026
Session fixation vulnerability in Edikon phpShop 0.8.1 allows remote attackers to hijack web sessions via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedMedium (6.8)2.0%💥 ExploitPhpshop2/12/20086/16/2026
SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as demonstrated by a shop/flypage action.
ModifiedHigh (7.5)2.6%—PhpshopAI12/31/20046/16/2026
PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.