Products: 1
Vulnerabilities: 16
Known Exploited: 0
2
Critical Level Threats
2
High Level Threats
12
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-36766
Authenticated XSS via Shopizer getInputStream and getReader in XssHttpServletRequestWrapper
Last Modified: May 02, 2026
Published: Apr 30, 2026
CVE-2026-36767
Arbitrary File Write via Path Traversal in Shopizer Image Upload
Last Modified: May 02, 2026
Published: Apr 30, 2026
CVE-2025-51605
An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, while also enabling Access-Control-Allow-Credentials: true. This allows any malicious origin to make authenticated cross-origin requests and read sensitive responses.
Last Modified: Sep 12, 2025
Published: Aug 22, 2025
CVE-2022-23063
Shopizer - Insufficient Session Expiration
Last Modified: Nov 21, 2024
Published: May 03, 2022
CVE-2022-23061
Shopizer - IDOR delete superadmin
Last Modified: Nov 21, 2024
Published: May 01, 2022
Items Per Page
