Products: 2
Vulnerabilities: 2
Known Exploited: 0
0
Critical Level Threats
1
High Level Threats
0
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2025-66572
Loaded Commerce 6.6 Client-Side Template Injection (CSTI)
Last Modified: May 26, 2026
Published: Dec 04, 2025
CVE-2014-5140
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.
Last Modified: Nov 21, 2024
Published: Jan 03, 2020
Items Per Page
