HikaShop
by Joomla
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38044 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-54364 | Med | 0.40 | 6.1 | 0.00 | Apr 9, 2026 | Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the… | ||
| CVE-2015-7344 | Med | 0.31 | 4.8 | 0.01 | Mar 9, 2020 | HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption]. | ||
| CVE-2026-61901 | Med | 0.00 | 6.1 | 0.00 | Jul 20, 2026 | Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect. |
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.40cvss 6.1epss 0.00
Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the…
- risk 0.31cvss 4.8epss 0.01
HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].
- risk 0.00cvss 6.1epss 0.00
Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.