P1 Unauthenticated SQL injection in order_tracking.php id/tracking_id parameter API8:2023 Security Misconfiguration / A03:2021 Injection (CWE-89)
Critical Critical severity vulnerability requires immediate attention regardless of remediation effort.
P1 Unauthenticated RCE on backend Apache 2.4.49 via double-encoded path traversal (CVE-2021-41773/42013 mod_cgi) A03:2021-Injection
Critical Critical severity vulnerability requires immediate attention regardless of remediation effort.
P1 Apache 2.4.49 front proxy: unauthenticated RCE via CVE-2021-42013 traversal + mod_cgi on /cgi-bin/ (POST to /bin/sh) A03:2021-Injection
Critical Critical severity vulnerability requires immediate attention regardless of remediation effort.
P1 Unauthenticated Twig SSTI leading to RCE on templates/preview?template= API8:2023 Security Misconfiguration / A03:2021 Injection
Critical Critical severity vulnerability requires immediate attention regardless of remediation effort.
P1 Unauthenticated Twig SSTI leading to RCE on invoices/create (POST template) A03:2021-Injection
Critical Critical severity vulnerability requires immediate attention regardless of remediation effort.
P1 Unauthenticated SQL injection in product_qa.php?product= (error-based and time-based blind) A03:2021 Injection (CWE-89)
Critical Critical severity vulnerability requires immediate attention regardless of remediation effort.
P1 Unauthenticated /api.php?action=secrets exposes production secrets and config in plaintext JSON A01:2021-Broken Access Control
Critical Critical severity vulnerability requires immediate attention regardless of remediation effort.
P1 Unauthenticated UNION-based SQL injection in promo.php?code= A03:2021-Injection
Critical Critical severity vulnerability requires immediate attention regardless of remediation effort.
P2 Unauthenticated SSRF and arbitrary local file read via check_link.php?url= A10:2021 Server-Side Request Forgery
Medium Medium severity with low remediation effort offers quick security win.
P2 Unauthenticated XXE in rss_parser.php xml_content parameter (arbitrary file read and SSRF) A03:2021 Injection (XXE)
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Unauthenticated arbitrary file read on backend Apache 2.4.49 via CVE-2021-41773/42013 path traversal A01:2021-Broken Access Control
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Apache 2.4.49 front proxy: CVE-2021-41773/42013 path traversal via %%32%65 and .%%32e encodings on /icons/ A01:2021-Broken Access Control
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Unauthenticated path traversal / arbitrary file read via /images/ on Apache 2.4.49 (CVE-2021-41773/42013) A01:2021-Broken Access Control
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Unauthenticated SQL injection in wishlist.php?id= (UNION-based and time-based blind) A03:2021-Injection
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Unauthenticated path traversal / arbitrary file read via view_media.php?file= API1:2023 Broken Object Level Authorization / A01:2021 Broken Access Control
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Unauthenticated path traversal / arbitrary file read via files/download?file= A01:2021 Broken Access Control
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Unauthenticated XXE in catalog/import xml_data import (arbitrary file read) A03:2021 Injection - XXE (CWE-611)
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Unauthenticated SQL injection in catalog/search?q= (boolean-blind, result-count oracle) API8:2023 Security Misconfiguration / A03:2021 Injection
High High severity vulnerability should be addressed promptly to reduce security risk.
P2 Reflected XSS on product_qa.php?product= via unescaped mysqli_error echo (alert fires in real browser) A03:2021-Injection
Medium Medium severity with low remediation effort offers quick security win.
P2 Reflected XSS on promo.php via unescaped mysqli_error echo (GET-link delivered) A03:2021 Injection
Medium Medium severity with low remediation effort offers quick security win.
P3 Unauthenticated SSRF with arbitrary file read via catalog/compare url1/url2/url3 A10:2021 Server-Side Request Forgery
Medium Medium severity vulnerability should be addressed in normal development cycle.
P4 Clickjacking: 37 pages missing frame-protection headers A04:2021 - Insecure Design
Low Low severity vulnerability can be addressed when resources allow.
P4 Clickjacking: 3 pages missing frame-protection headers A04:2021 - Insecure Design
Low Low severity vulnerability can be addressed when resources allow.
P4 Missing Security Headers across 37 pages A05:2021 - Security Misconfiguration
Info Address when time and resources permit.
P4 Missing Security Headers across 3 pages A05:2021 - Security Misconfiguration
Info Address when time and resources permit.
P4 Session/Auth Cookie Missing Security Flags A05:2021 - Security Misconfiguration
Low Low severity vulnerability can be addressed when resources allow.
P4 Session/Auth Cookie Missing Security Flags A05:2021 - Security Misconfiguration
Info Address when time and resources permit.
P4 Unvalidated open redirect on external_link.php?url= A01:2021 Broken Access Control (Unvalidated Redirects)
Low Low severity vulnerability can be addressed when resources allow.
P4 Stack version disclosure: Apache/2.4.54, PHP/7.4.33 (EOL) in response headers A05:2021-Security Misconfiguration
Low Low severity vulnerability can be addressed when resources allow.
P4 Unauthenticated XML product import allows arbitrary catalog content injection (catalog/import) A01:2021-Broken Access Control
Low Low severity vulnerability can be addressed when resources allow.
P4 javascript: URI rendered raw in feed-link href (link injection) A03:2021-Injection
Low Low severity vulnerability can be addressed when resources allow.
P4 Reflected XSS in invoices/create - template echoed unescaped into Invoice Preview div A03:2021-Injection
Low Low severity vulnerability can be addressed when resources allow.
P4 Unvalidated open redirect on redirect.php?url= A01:2021-Broken Access Control
Info Address when time and resources permit.
P4 Options Indexes directory listing exposed on front-proxy /icons/ alias A05:2021-Security Misconfiguration
Info Address when time and resources permit.