Shoppingtree
6 CVEs tracked since 2008. Since Feb 2008, none of them reached CISA KEV.
Shoppingtree CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2008-02 | 6 | 0 |
Products
The products that kept showing up in Shoppingtree's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 6 most recently published vulnerabilities affecting Shoppingtree.
- CVE-2008-0739SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAcco...7.5
- CVE-2008-0738Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_get...7.5
- CVE-2008-0736admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter.5.0
- CVE-2008-0737SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfiel...7.5
- CVE-2008-0547Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web sc...4.3
- CVE-2008-0546Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parame...7.5
The record
- Peak rank
- #21 in Feb 2008
- Busiest month shown
- Feb 2008, 6 CVEs
- Months with a KEV entry
- 0 since Feb 2008
- Monthly snapshots
- 1 since 2008