Abantecart

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 11
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-50972

    SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index.php. Three techniques have been demonstrated: error-based injection using a crafted FLOOR-based payload, time-based blind injection via SLEEP(), and UNION-based injection to extract arbitrary data.

    Last Modified: Sep 08, 2025
    Published: Aug 27, 2025

    CVE-2025-50971

    Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.

    Last Modified: Sep 04, 2025
    Published: Aug 26, 2025

    CVE-2025-40627

    Reflected Cross-Site Scripting (XSS) in AbanteCart

    Last Modified: Oct 10, 2025
    Published: May 12, 2025

    CVE-2025-40626

    Reflected Cross-Site Scripting (XSS) in AbanteCart

    Last Modified: Oct 10, 2025
    Published: May 12, 2025

    CVE-2024-50801

    A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter.

    Last Modified: Sep 04, 2025
    Published: Oct 31, 2024
    Items Per Page