VYPR

Commerce

by HCL Software

CVEs (8)

  • CVE-2022-38656HigDec 12, 2022
    risk 0.56cvss 8.6epss 0.01

    HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.

  • CVE-2020-14274HigJan 12, 2021
    risk 0.49cvss 7.5epss 0.01

    Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.

  • CVE-2024-23576HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2023-37532MedOct 23, 2023
    risk 0.38cvss 5.8epss 0.01

    HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

  • CVE-2021-27751MedMay 6, 2022
    risk 0.29cvss 4.4epss 0.00

    HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.

  • CVE-2021-27758MedMay 6, 2022
    risk 0.28cvss 4.3epss 0.00

    There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.

  • CVE-2021-27785LowJul 30, 2022
    risk 0.25cvss 3.9epss 0.00

    HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.

  • CVE-2026-21824HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.