SimplCommerce
Simplcommerce · 2 CVEs
CVE-2026-9591
MEDIUM
Cross-Site Request Forgery (CSRF) in SimplCommerce News Module
Jun 17, 2026
CVE-2026-11975
MEDIUM
Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface
Jun 17, 2026
CVE-2020-27478
HIGH
Cross Site Scripting vulnerability found in Simplcommerce v.40734964b0811f3cbaf64b6dac261683d256f961 thru 3103357200c70…
Apr 30, 2024
CVE-2020-29587
MEDIUM
SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap…
Jan 14, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-9591 | Cross-Site Request Forgery (CSRF) in SimplCommerce News Module | MEDIUM | 0.28% | Jun 17, 2026 |
| CVE-2026-11975 | Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface | MEDIUM | 0.26% | Jun 17, 2026 |
| CVE-2020-27478 | Cross Site Scripting vulnerability found in Simplcommerce v.40734964b0811f3cbaf64b6dac261683d256f961 thru 3103357200c70b4767986544e01b19dbf11505a7 allows a rem… | HIGH | 0.46% | Apr 30, 2024 |
| CVE-2020-29587 | SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap modals. The Bootbox.js library intention… | MEDIUM | 0.68% | Jan 14, 2021 |
Showing 1 to 2 of 2 CVEs