52
I Use This!
Activity Not Available
Analyzed over 2 years ago. based on code collected about 4 years ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2020-29070 BDSA-2020-3539 Medium Nov 25, 2020 osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
v2.3.4.1
CVE-2020-23360 BDSA-2020-4120 Critical Jan 27, 2021 oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /cat more...
v2.3.4.1
CVE-2019-25497 BDSA-2019-5443 High Feb 27, 2026 osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th more...
v2.3.4.1, v2.3.4, v2.3.3.4, v2.3.3.3, v2.3.3.2, v2.3.3.1, 2.3.3, 2.3.2, 2.3.1, 2.3
CVE-2019-25496 BDSA-2019-5442 High Feb 27, 2026 osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th more...
v2.3.4.1
CVE-2019-25495 BDSA-2019-5441 High Feb 27, 2026 osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th more...
v2.3.4.1
CVE-2018-18966 BDSA-2018-3947 Medium Nov 06, 2018 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html ext more...
v2.3.4.1
CVE-2018-18965 BDSA-2018-3946 Medium Nov 06, 2018 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html ext more...
v2.3.4.1
CVE-2018-18964 BDSA-2018-3945 Medium Nov 06, 2018 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html ext more...
v2.3.4.1
CVE-2018-18573 BDSA-2018-3949 High Aug 22, 2019 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.ht more...
v2.3.4.1
CVE-2018-18572 BDSA-2018-3948 High Aug 22, 2019 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-r more...
v2.3.4.1