← Back

Bugmall

bugmall

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Shopping Cart
shopping_cart

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bugmall
1Shopping Cart
Apr 23, 2026
Jun 27, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might...Show more
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.Show less
1Bugmall
1Shopping Cart
Apr 23, 2026
Jun 27, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.
1Bugmall
1Shopping Cart
Apr 23, 2026
Jun 27, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.