Vulnerabilities (CVE)

Filtered by vendor Ectouch Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-39560 1 Ectouch 1 Ectouch 2024-02-28 N/A 9.8 CRITICAL
ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.
CVE-2022-25098 1 Ectouch 1 Ectouch 2024-02-28 6.4 MEDIUM 9.1 CRITICAL
ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.
CVE-2020-18144 1 Ectouch 1 Ectouch 2024-02-28 7.5 HIGH 9.8 CRITICAL
SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.
CVE-2020-21806 1 Ectouch 1 Ectouch 2024-02-28 7.5 HIGH 9.8 CRITICAL
SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..