Vulnerabilities > EC Cube > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-28 CVE-2021-20750 Cross-site Scripting vulnerability in Ec-Cube
Cross-site scripting vulnerability in EC-CUBE EC-CUBE 3.0.0 to 3.0.18-p2 (EC-CUBE 3 series) and EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.
network
ec-cube CWE-79
4.3
2021-06-28 CVE-2021-20751 Cross-site Scripting vulnerability in Ec-Cube
Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.
network
ec-cube CWE-79
4.3
2021-06-22 CVE-2021-20735 Cross-site Scripting vulnerability in Ec-Cube products
Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earlier, and Delivery slip number mail plugin (3.0 series) 1.0.8 and earlier) allows remote attackers to inject an arbitrary script by executing a specific operation on the management page of EC-CUBE.
network
ec-cube CWE-79
4.3
2021-06-22 CVE-2021-20742 Cross-site Scripting vulnerability in Ec-Cube Business Form Output
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.
network
ec-cube CWE-79
4.3
2021-06-22 CVE-2021-20743 Cross-site Scripting vulnerability in Ec-Cube Email Newsletters Management
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.
network
ec-cube CWE-79
4.3
2021-06-22 CVE-2021-20744 Cross-site Scripting vulnerability in Ec-Cube Business Form Output
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.
network
ec-cube CWE-79
4.3
2021-05-10 CVE-2021-20717 Cross-site Scripting vulnerability in Ec-Cube
Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is created using EC-CUBE.
network
ec-cube CWE-79
4.3
2020-12-03 CVE-2020-5680 Improper Input Validation vulnerability in Ec-Cube
Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector.
network
low complexity
ec-cube CWE-20
5.0
2020-12-03 CVE-2020-5679 Improper Restriction of Rendered UI Layers or Frames vulnerability in Ec-Cube
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks.
network
ec-cube CWE-1021
4.3
2020-06-19 CVE-2020-5590 Path Traversal vulnerability in Ec-Cube
Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.
network
low complexity
ec-cube CWE-22
5.5