Filtered by vendor Ectouch Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-39560 1 Ectouch 1 Ectouch 2024-10-02 9.8 Critical
ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.
CVE-2020-21806 1 Ectouch 1 Ectouch 2024-08-04 9.8 Critical
SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..
CVE-2020-18144 1 Ectouch 1 Ectouch 2024-08-04 9.8 Critical
SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.
CVE-2022-25098 1 Ectouch 1 Ectouch 2024-08-03 9.1 Critical
ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.