Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Projectworlds Subscribe
Filtered by product Online Shopping System In Php
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-43157 1 Projectworlds 1 Online Shopping System In Php 2021-12-28 7.5 HIGH 9.8 CRITICAL
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
CVE-2021-43158 1 Projectworlds 1 Online Shopping System In Php 2021-12-28 4.3 MEDIUM 4.3 MEDIUM
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.