Vulnerabilities > Shopfiles

DATE CVE VULNERABILITY TITLE RISK
2024-12-21 CVE-2024-11287 Cross-site Scripting vulnerability in Shopfiles Ebook Store
The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.8001.
network
low complexity
shopfiles CWE-79
6.1
2024-12-21 CVE-2024-12262 Cross-site Scripting vulnerability in Shopfiles Ebook Store
The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all versions up to, and including, 5.8001 due to insufficient input sanitization and output escaping.
network
low complexity
shopfiles CWE-79
6.1
2024-12-09 CVE-2023-22701 Unspecified vulnerability in Shopfiles Ebook Store
Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.
network
low complexity
shopfiles
critical
9.8
2024-02-29 CVE-2024-23501 Unspecified vulnerability in Shopfiles Ebook Store
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Ebook Store allows Stored XSS.This issue affects Ebook Store: from n/a through 5.788.
network
low complexity
shopfiles
4.8
2023-10-18 CVE-2023-45602 Unspecified vulnerability in Shopfiles Ebook Store
Unauth.
network
low complexity
shopfiles
6.1
2023-05-15 CVE-2023-22690 Unspecified vulnerability in Shopfiles Ebook Store
Auth.
network
low complexity
shopfiles
4.8