Vulnerabilities (CVE)

Filtered by vendor Potenzaglobalsolutions
Filtered by product Ciyashop
Angry Yack Logo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-39349 1 Potenzaglobalsolutions 1 Ciyashop 2025-05-29 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop allows Object Injection.This issue affects CiyaShop: from n/a through 4.18.0.
CVE-2024-13824 1 Potenzaglobalsolutions 1 Ciyashop 2025-03-21 N/A 9.8 CRITICAL
The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 via deserialization of untrusted input in the 'add_ciyashop_wishlist' and 'ciyashop_get_compare' functions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is instal ...

Show More