Fabian E-Commerce Site vulnerabilities

4 known vulnerabilities affecting fabian/e-commerce_site.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2025-11094MEDIUMCVSS 6.9v1.02025-09-28
CVE-2025-11094 [MEDIUM] CWE-74 CVE-2025-11094: A security vulnerability has been detected in code-projects E-Commerce Website 1.0. This affects an A security vulnerability has been detected in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/admin_product_details.php. Such manipulation of the argument prod_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-7756MEDIUMCVSS 5.3v1.02025-07-17
CVE-2025-7756 [MEDIUM] CWE-352 CVE-2025-7756: A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affec A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-7175MEDIUMCVSS 5.3v1.02025-07-08
CVE-2025-7175 [MEDIUM] CWE-284 CVE-2025-7175: A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2023-7124MEDIUMCVSS 6.1v1.02023-12-28
CVE-2023-7124 [MEDIUM] CWE-79 CVE-2023-7124: A vulnerability, which was classified as problematic, was found in code-projects E-Commerce Site 1.0 A vulnerability, which was classified as problematic, was found in code-projects E-Commerce Site 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument keyword with the input leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. T
nvd