oscommerce security advisories
2 threat alerts tracking vulnerabilities and security advisories that affect oscommerce products.
Vulnios monitors oscommerce CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent oscommerce security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2020-23360 — oscommerce — oscommerce
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/passwo
criticalCVE-2020-23360Critical Vulnerability: CVE-2020-27976 — oscommerce — oscommerce
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the se
criticalCVE-2020-27976
Track oscommerce exposure across your environment
Vulnios automatically cross-references your asset inventory against new oscommerce CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan