CVE Tools

Shopizer

5 CVEs tracked since 2014. Since Jul 2014, none of them reached CISA KEV.

Shopizer CVEs per month

Jul 2014 to Aug 2014. Point at a month, or focus the strip and use the arrow keys.
Shopizer CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-0740
2014-0810

Products

The products that kept showing up in Shopizer's monthly top three, with their CVEs summed over those months.

  1. Shopizer52 months

Latest CVEs

The 14 most recently published vulnerabilities affecting Shopizer.

  1. CVE-2025-51605An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, wh...8.1
  2. CVE-2022-23063Shopizer - Insufficient Session Expiration8.8
  3. CVE-2022-23061Shopizer - IDOR delete superadmin6.5
  4. CVE-2022-23060Shopizer - Stored XSS in Manage Files4.8
  5. CVE-2022-23059Shopizer - Stored XSS in Manage Images4.8
  6. CVE-2021-33561A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration...4.8
  7. CVE-2021-33562A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary prod...4.8
  8. CVE-2020-11006Potential remote code execution in Shopizer9.1
  9. CVE-2020-11007Negative charge in shopping cart possible in Shopizer6.5
  10. CVE-2014-5385com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which makes it easier for remote attackers to guess passwo...5.0
  11. CVE-2014-4962Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be s...6.4
  12. CVE-2014-4965Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) customername parameter to central/orders/...4.3
  13. CVE-2014-4963Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.6.8
  14. CVE-2014-4964Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users for requests that (1) modify customer settings ...6.8

The record

Peak rank
#39 in Jul 2014
Busiest month shown
Jul 2014, 4 CVEs
Months with a KEV entry
0 since Jul 2014
Monthly snapshots
2 since 2014
Shopizer's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store