Oxid-esales

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    2
    Critical Level Threats
    7
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-25260

    OXID eShop 6.3.4 - 'sorting' SQL Injection

    Last Modified: Jul 15, 2026
    Published: Feb 03, 2026

    CVE-2024-56526

    An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.

    Last Modified: Jan 29, 2026
    Published: May 13, 2025

    CVE-2023-38330

    OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.

    Last Modified: Nov 21, 2024
    Published: Aug 02, 2023

    CVE-2019-17062

    An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users with administrative rights could unintentionally grant unauthorized users access to the admin panel via session fixation.

    Last Modified: Nov 21, 2024
    Published: Nov 05, 2019

    CVE-2019-13026

    OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.

    Last Modified: Nov 21, 2024
    Published: Jul 30, 2019
    Items Per Page
    Oxid-Esales Vulnerabilities & Security CVEs | CVE-DB