Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Os Commerce — Vulnerabilities & Security Advisories 36

Browse all 36 CVE security advisories affecting Os Commerce. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OsCommerce is an open-source e-commerce platform designed to facilitate online retail operations through customizable storefronts and inventory management. Historically, its widespread adoption in the early 2000s coincided with a high prevalence of critical security flaws, resulting in 36 recorded CVEs. Common vulnerability classes include remote code execution, cross-site scripting, and SQL injection, often stemming from insufficient input validation and outdated authentication mechanisms. Privilege escalation issues have also been documented, allowing unauthorized users to gain administrative access. The software’s modular architecture, while flexible, frequently introduced security gaps when third-party contributions lacked rigorous review. Major incidents often involved automated exploitation of known unpatched vulnerabilities, leading to data breaches and defacement. Consequently, maintaining secure deployments requires diligent patch management and strict adherence to security best practices, as the platform’s legacy codebase presents inherent risks if not properly hardened against contemporary attack vectors.

Top products by Os Commerce: Os Commerce
CVE IDTitleCVSSSeverityPublished
CVE-2023-5112 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-5111 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43735 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43734 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43733 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43732 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43731 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43730 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43729 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43728 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43727 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43726 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43725 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43724 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43723 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43722 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43721 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43720 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43719 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43718 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43717 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43716 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43715 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43714 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43713 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43712 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43711 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43710 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43709 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30
CVE-2023-43708 Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS) — Os CommerceCWE-79 5.4 Medium2023-09-30

This page lists every published CVE security advisory associated with Os Commerce. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.