CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Dec 29, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3...Show more |
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Dec 4, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks,...Show more |
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Nov 23, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.26 versions. |
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Jul 1, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.17. This is due to missing or incorrect nonce validation on the sa...Show more |
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Jul 1, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the im...Show more |
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Apr 7, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.4 versions. |
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Mar 17, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 3.3.8 due to insufficient input sanitization and outpu...Show more |
1Implecode 1Ecommerce Product Catalog Jun 17, 2026 Nov 23, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting...Show more |