Vulnerabilities > EC Cube > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-09-27 CVE-2022-37346 Unrestricted Upload of File with Dangerous Type vulnerability in Ec-Cube Product Image Bulk Upload 1.0.0/4.1.0
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files.
network
low complexity
ec-cube CWE-434
critical
9.8
2016-08-01 CVE-2016-4837 SQL Injection vulnerability in Ec-Cube Discount Coupon
SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
ec-cube CWE-89
critical
9.8