xt:Commerce 3 suffers from a second order SQL injection vulnerability that can be leveraged to reset passwords of arbitrary users and administrators.
9e3a37b7a87b6f0a5036cf569879b12c6788f73c69e4a9ca19a78276984e9a6f
CakePHP versions 1.3.5 and below and 1.2.8 and below unserialize() cache corruption exploit.
65a2b440d4696ecb893de017fe9da620c3ac3cbfb1083146551fa48a1d51dc2a