Vulnerabilities > Shopwind

DATE CVE VULNERABILITY TITLE RISK
2022-11-09 CVE-2022-43321 Cross-site Scripting vulnerability in Shopwind 3.4.3
Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.
network
low complexity
shopwind CWE-79
6.1
2022-05-11 CVE-2022-30057 Cross-site Scripting vulnerability in Shopwind
Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.
network
low complexity
shopwind CWE-79
5.4
2022-05-11 CVE-2022-30058 Path Traversal vulnerability in Shopwind
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.php.
network
low complexity
shopwind CWE-22
5.3
2022-05-11 CVE-2022-30059 Path Traversal vulnerability in Shopwind
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php.
network
low complexity
shopwind CWE-22
6.5
2022-05-11 CVE-2022-30452 SQL Injection vulnerability in Shopwind
ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php
network
low complexity
shopwind CWE-89
7.2
2022-05-11 CVE-2022-30453 Unspecified vulnerability in Shopwind
ShopWind <= 3.4.2 has a RCE vulnerability in Database.php
network
low complexity
shopwind
critical
9.8