VYPR
Vendor

OsCommerce

OsCommerce is an e-commerce software solution. It can be used on any web server that has PHP and MySQL installed. It is available as free software under the GNU General Public License.

Founded 2000
Products
20
CVEs
98
Across products
118
Status
Private

Products

20

Recent CVEs

98
View all 98 CVEs →
  • CVE-2009-20006CriSep 16, 2025
    risk 0.64cvss epss 0.01

    osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft…

  • CVE-2018-25114CriJul 23, 2025
    risk 0.64cvss epss 0.03

    A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after installation. An…

  • CVE-2020-23360CriJan 27, 2021
    risk 0.64cvss 9.8epss 0.01

    oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php

  • CVE-2020-27976CriOct 28, 2020
    risk 0.64cvss 9.8epss 0.07

    osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.

  • CVE-2020-27975HigOct 28, 2020
    risk 0.57cvss 8.8epss 0.01

    osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.

  • CVE-2019-25497HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the currency parameter. Attackers can send GET requests to shopping_cart.php with malicious currency values using…

  • CVE-2019-25496HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the products_id parameter. Attackers can modify the products_id value in product_info.php requests and append…

  • CVE-2019-25495HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the reviews_id parameter. Attackers can send GET requests to product_reviews_write.php with malicious reviews_id values…

  • CVE-2023-6579HigDec 7, 2023
    risk 0.49cvss 7.3epss 0.24

    A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argument estimate[country_id] leads…

  • CVE-2018-18573HigAug 22, 2019
    risk 0.47cvss 7.2epss 0.03

    osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code execution via a…

  • CVE-2018-18572HigAug 22, 2019
    risk 0.47cvss 7.2epss 0.03

    osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht'…

  • CVE-2024-22724MedMar 21, 2024
    risk 0.43cvss 6.6epss 0.00

    An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

  • CVE-2022-35212MedAug 18, 2022
    risk 0.40cvss 6.1epss 0.00

    osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().

  • CVE-2023-5112MedSep 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "specials_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

  • CVE-2023-5111MedSep 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "featured_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

  • CVE-2023-43735MedSep 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "formats_titles[7]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

  • CVE-2023-43734MedSep 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

  • CVE-2023-43733MedSep 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "company_address" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

  • CVE-2023-43732MedSep 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tax_class_title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

  • CVE-2023-43731MedSep 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "zone_name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.