VYPR

Ecommerce Website

by Codeastro

CVEs (5)

  • CVE-2024-2351MedMar 9, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in CodeAstro Ecommerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file action.php of the component Search. The manipulation of the argument cat_id/brand_id/keyword leads to sql injection. The…

  • CVE-2025-9237LowAug 20, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is…

  • CVE-2026-14799MedJul 6, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit…

  • CVE-2026-14767MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack…

  • CVE-2026-14639MedJul 4, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The…