VYPR

Smart Shop

by Smart Shop

CVEs (5)

  • CVE-2018-25342HigMay 23, 2026
    risk 0.53cvss 8.2epss 0.00

    Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in search.php. Attackers can send GET requests with malicious SQL payloads like SLEEP…

  • CVE-2018-25341HigMay 23, 2026
    risk 0.53cvss 8.2epss 0.00

    Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id…

  • CVE-2018-25340HigMay 23, 2026
    risk 0.53cvss 8.2epss 0.00

    Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to category.php with UNION-based SQL injection payloads in the id…

  • CVE-2018-25343MedMay 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting editprofile.php with hidden fields for email and password…

  • CVE-2007-5725Oct 30, 2007
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Smart-Shop allow remote attackers to inject arbitrary web script or HTML via (1) the email parameter to index.php; or the command parameter to index.php in (2) the default action for the home page, (3) a currencies action,…