Oxidforge

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-25260

    OXID eShop 6.3.4 - 'sorting' SQL Injection

    Last Modified: Jul 15, 2026
    Published: Feb 03, 2026

    CVE-2023-26260

    OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.

    Last Modified: Feb 11, 2025
    Published: Apr 11, 2023

    CVE-2014-2017

    CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Last Modified: Nov 21, 2024
    Published: Jan 18, 2018

    CVE-2016-5072

    OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition v4.8.12, Community Edition v4.9.9.

    Last Modified: Apr 20, 2025
    Published: Apr 10, 2017

    CVE-2009-3112

    Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop backend via a crafted parameter.

    Last Modified: Apr 23, 2026
    Published: Sep 09, 2009
    Items Per Page