Qualiteam

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-7220

    X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter.

    Last Modified: Nov 21, 2024
    Published: Jun 06, 2019

    CVE-2017-15285

    X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before saving locally. This vulnerability can be exploited by anyone with Vendor access or higher. One attack methodology is to upload an image file in the Attachments section of a product catalog, upload a .php file with an "Add File Via URL" action, and change the image's Description URL to reference the .php URL in the attachments/ directory.

    Last Modified: Apr 20, 2025
    Published: Oct 12, 2017

    CVE-2015-5455

    Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to install/.

    Last Modified: Apr 12, 2025
    Published: Jul 08, 2015

    CVE-2015-0950

    Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter.

    Last Modified: Apr 12, 2025
    Published: Apr 05, 2015

    CVE-2015-0951

    X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request.

    Last Modified: Apr 12, 2025
    Published: Apr 05, 2015
    Items Per Page
    Qualiteam Vulnerabilities & Security CVEs | CVE-DB