Kiril Kirkov

22 exploits Active since Sep 2020
CVE-2026-14632 WRITEUP MEDIUM WRITEUP
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Trusted Backend MY_Controller.php setReferrer redirect
A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. The manipulation of the argument href results in open redirect. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The patch is identified as 213babdbaa949e94557246414db0130e01394517. A patch should be applied to remediate this issue.
CVSS 4.3
CVE-2026-14633 WRITEUP MEDIUM WRITEUP
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cross site scripting
A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument title/description causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Patch name: d9785f995da77bdc62fb2d34bad5f7a162c9ad23. To fix this issue, it is recommended to deploy a patch.
CVSS 4.3
CVE-2026-14634 WRITEUP MEDIUM WRITEUP
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Subscribed Emails Admin MY_Controller.php checkForPostRequests cross site scripting
A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. Such manipulation of the argument User-Agent leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The name of the patch is 23105f25dadf57b4314fc015a63a7c6e910c89df. It is advisable to implement a patch to correct this issue.
CVSS 4.3
CVE-2026-14635 WRITEUP HIGH WRITEUP
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal
A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the argument folder results in path traversal. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The patch is named 2a9497ff11f36e573ad99e1c357ff0e6ded49745. Applying a patch is the recommended action to fix this issue.
CVSS 7.3
CVE-2026-14636 WRITEUP MEDIUM WRITEUP
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversal
A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the argument folder can lead to path traversal. It is possible to launch the attack remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. This patch is called de1c9e73ccf3bd032d9a0525c4752290d959dd8b. It is best practice to apply a patch to resolve this issue.
CVSS 5.4
CVE-2026-14637 WRITEUP HIGH WRITEUP
kirilkirkov Ecommerce-CodeIgniter-Bootstrap ShoppingCart.php getCartItems deserialization
A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The identifier of the patch is 49b20f53de2b7ec34e920b11c863f1491d911a04. It is recommended to apply a patch to fix this issue.
CVSS 8.2
CVE-2020-25086 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2020-08-03 - Cross-Site Scripting in adminUsers.php
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
CVSS 6.1
CVE-2020-25087 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2020-08-03 - Cross-Site Scripting in Languages Settings Page
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
CVSS 6.1
CVE-2020-25088 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2020-08-03 - Cross-Site Scripting in Blog Publish View
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
CVSS 6.1
CVE-2020-25089 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2020-08-03 - Cross-Site Scripting in Discounts Admin View
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
CVSS 6.1
CVE-2020-25090 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2020-08-03 - Cross-Site Scripting in Admin Publish View
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
CVSS 6.1
CVE-2020-25091 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2020-08-03 - Cross-Site Scripting in add_product.php
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
CVSS 6.1
CVE-2020-25092 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2020-08-03 - Cross-Site Scripting in Header Template
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel.
CVSS 6.1
CVE-2020-25093 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2020-08-03 - Cross-Site Scripting in blog.php
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
CVSS 6.1
CVE-2022-35213 WRITEUP MEDIUM WRITEUP
ecommerce-codeigniter-bootstrap < 2021-08-21 - Cross-Site Scripting via base_url() Function
Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php.
CVSS 6.1
CVE-2023-23010 WRITEUP MEDIUM WRITEUP
Ecommerce-CodeIgniter-Bootstrap < 2022-12-27 - Cross-Site Scripting via Languages and Trans Load Parameters
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.
CVSS 6.1
CVE-2024-31820 WRITEUP CRITICAL WRITEUP
ecommerce-codeigniter-bootstrap < 2024-01-02 - Remote Code Execution via getLangFolderForEdit Method
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.
CVSS 9.8
CVE-2024-31821 WRITEUP HIGH WRITEUP
Ecommerce-CodeIgniter-Bootstrap <d22b54e - SQL Injection
SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.
CVSS 8.0
CVE-2024-31822 WRITEUP CRITICAL WRITEUP
Ecommerce-CodeIgniter-Bootstrap <d22b54e - RCE
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.
CVSS 9.8
CVE-2024-31823 WRITEUP HIGH WRITEUP
Ecommerce-CodeIgniter-Bootstrap - Remote Code Execution via Publish.php removeSecondaryImage Method
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.
CVSS 8.8
CVE-2024-6526 WRITEUP LOW WRITEUP
ecommerce-codeigniter-bootstrap < 2024-07-03 - XSS via search_title/catName/sub/name/categorie
A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 1b3da45308bb6c3f55247d0e99620b600bd85277. It is recommended to apply a patch to fix this issue. The identifier VDB-270369 was assigned to this vulnerability.
CVSS 3.5
CVE-2024-7067 WRITEUP MEDIUM WRITEUP
shuttur/ecommerce-laravel-bootstrap < 2024-07-03 - Deserialization of Untrusted Data in getCartProductsIds
A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. Affected by this issue is the function getCartProductsIds of the file app/Cart.php. The manipulation of the argument laraCart leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The name of the patch is a02111a674ab49f65018b31da3011b1e396f59b1. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-272348.
CVSS 6.3