VYPR
Vendor

Hikashop

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2023-38044CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2025-22210HigFeb 25, 2025
    risk 0.47cvss 7.2epss 0.01

    A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.

  • CVE-2025-25225MedMar 15, 2025
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions.

  • CVE-2024-40746MedOct 21, 2024
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description…

  • CVE-2015-7344MedMar 9, 2020
    risk 0.31cvss 4.8epss 0.01

    HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].