Vulnerabilities > Collne > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-28 CVE-2023-50847 Unspecified vulnerability in Collne Welcart E-Commerce
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Collne Inc.
network
low complexity
collne
7.2
2023-12-04 CVE-2023-5953 Unrestricted Upload of File with Dangerous Type vulnerability in Collne Welcart E-Commerce
The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload.
network
low complexity
collne CWE-434
8.8
2023-09-27 CVE-2023-40219 Unrestricted Upload of File with Dangerous Type vulnerability in Collne Welcart E-Commerce
Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.
network
low complexity
collne CWE-434
7.2
2023-09-27 CVE-2023-43610 SQL Injection vulnerability in Collne Welcart E-Commerce
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
network
low complexity
collne CWE-89
8.8
2023-01-02 CVE-2022-4140 Unspecified vulnerability in Collne Welcart E-Commerce
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
network
low complexity
collne
7.5
2023-01-02 CVE-2022-4237 Unspecified vulnerability in Collne Welcart E-Commerce
The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscriber to perform PHAR deserialisation when they can upload a file and a suitable gadget chain is present on the blog
network
low complexity
collne
8.8
2020-11-07 CVE-2020-28339 Deserialization of Untrusted Data vulnerability in Collne Welcart E-Commerce
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize.
network
low complexity
collne CWE-502
8.8