<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:05:53.483381+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-33590</id>
    <title>cnvd-2020-33590</title>
    <updated>2026-10-08T08:05:53.550745+00:00</updated>
    <content>cnvd-2020-33590</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-33590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-40278</id>
    <title>EUVD-2026-40278</title>
    <updated>2026-10-08T08:05:53.550787+00:00</updated>
    <content>EUVD-2026-40278</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-40278"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11007</id>
    <title>fkie_cve-2020-11007</title>
    <updated>2026-10-08T08:05:53.550803+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patched in version 2.11.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-11007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w8rc-pgxq-x2cj</id>
    <title>GHSA-w8rc-pgxq-x2cj — Negative charge in shopping cart in Shopizer</title>
    <updated>2026-10-08T08:05:53.550834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.shopizer:sm-core-model</p>
<p>### Impact
Using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total.</p>
<p>### Patches
Adding a back-end verification to check that quantity parameter isn't negative. If so, it is set to 1. Patched in 2.11.0</p>
<p>### Workarounds
Without uprading, it's possible to just apply the fixes in the same files it's done for the patch. Or you use javax constraint validation on the quantity parameter.</p>
<p>### References
[Input Validation](https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html)
[Using bean validation constraint](https://javaee.github.io/tutorial/bean-validation002.html)
[Commits with fixes](https://github.com/shopizer-ecommerce/shopizer/commit/929ca0839a80c6f4dad087e0259089908787ad2a)
CVE Details below : 
[Mitre](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11007)
[NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-11007)</p>
<p>### Credits
Found and solved by Yannick Gosset from Aix-Marseille University cybersecurity
master program supervised by Yassine Ilmi</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w8rc-pgxq-x2cj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-11007</id>
    <title>gsd-2020-11007</title>
    <updated>2026-10-08T08:05:53.550879+00:00</updated>
    <content>gsd-2020-11007</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-11007"/>
  </entry>
</feed>
