Shopizer

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 16
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    12
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-36766

    Authenticated XSS via Shopizer getInputStream and getReader in XssHttpServletRequestWrapper

    Last Modified: May 02, 2026
    Published: Apr 30, 2026

    CVE-2026-36767

    Arbitrary File Write via Path Traversal in Shopizer Image Upload

    Last Modified: May 02, 2026
    Published: Apr 30, 2026

    CVE-2025-51605

    An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, while also enabling Access-Control-Allow-Credentials: true. This allows any malicious origin to make authenticated cross-origin requests and read sensitive responses.

    Last Modified: Sep 12, 2025
    Published: Aug 22, 2025

    CVE-2022-23063

    Shopizer - Insufficient Session Expiration

    Last Modified: Nov 21, 2024
    Published: May 03, 2022

    CVE-2022-23061

    Shopizer - IDOR delete superadmin

    Last Modified: Nov 21, 2024
    Published: May 01, 2022
    Items Per Page