← Back

Merchandise Online Store

merchandise_online_store

Vendor: Merchandise Online Store Project • 20 CVEs

CVEs (20)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
Oct 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
Oct 11, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
Oct 11, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=product/manage_product&id=.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 13, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.