| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-47110 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | Adobe | Adobe Commerce | High | 8.4 | 2025-06-10 16:08:56 | Deep Dive |
| CVE-2025-43586 | Adobe Commerce | Improper Access Control (CWE-284) | Adobe | Adobe Commerce | High | 8.1 | 2025-06-10 16:08:56 | Deep Dive |
| CVE-2025-27207 | Adobe Commerce | Improper Access Control (CWE-284) | Adobe | Adobe Commerce | Medium | 6.5 | 2025-06-10 16:08:55 | Deep Dive |
| CVE-2025-43585 | Adobe Commerce | Improper Authorization (CWE-285) | Adobe | Adobe Commerce | High | 8.2 | 2025-06-10 16:08:54 | Deep Dive |
| CVE-2025-47511 | WordPress Welcart e-Commerce plugin <= 2.11.13 - Arbitrary File Deletion Vulnerability | info@welcart | Welcart e-Commerce | Medium | 6.8 | 2025-06-09 15:54:11 | Deep Dive |
| CVE-2025-48123 | WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin <= 2.4.37 - Remote Code Execution (RCE) Vulnerability | Holest Engineering | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | Critical | 10.0 | 2025-06-09 15:54:06 | Deep Dive |
| CVE-2025-48122 | WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin <= 2.4.37 - SQL Injection Vulnerability | Holest Engineering | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | Critical | 9.3 | 2025-06-09 15:54:06 | Deep Dive |
| CVE-2025-48124 | WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin <= 2.4.37 - Arbitrary File Download Vulnerability | Holest Engineering | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | High | 7.5 | 2025-06-09 15:54:05 | Deep Dive |
| CVE-2025-48129 | WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin <= 2.4.37 - Privilege Escalation Vulnerability | Holest Engineering | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | Critical | 9.8 | 2025-06-09 15:54:03 | Deep Dive |
| CVE-2025-4631 | Profitori 2.0.6.0 - 2.1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation via stocktend_object Endpoint | unitybusinesstechnology | The E-Commerce ERP: Purchasing, Inventory, Fulfillment, Manufacturing, BOM, Accounting, Sales Analysis | Critical | 9.8 | 2025-05-31 06:40:58 | Deep Dive |
| CVE-2025-47657 | WordPress Productive Commerce plugin <= 1.1.42 - SQL Injection vulnerability | Productive Minds | Productive Commerce | Critical | 9.3 | 2025-05-07 14:20:47 | Deep Dive |
| CVE-2025-3852 | WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover | eoxia | WPshop 2 – E-Commerce | High | 8.8 | 2025-05-07 01:43:09 | Deep Dive |
| CVE-2025-3853 | WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Key Generation | eoxia | WPshop 2 – E-Commerce | Medium | 6.5 | 2025-05-07 01:43:06 | Deep Dive |
| CVE-2024-11142 | CSRF in Gosoft Software's Proticaret E-Commerce | Gosoft Software | Proticaret E-Commerce | High | 8.8 | 2025-05-02 07:47:30 | Deep Dive |
| CVE-2025-39378 | WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin <= 2.4.37 - Local File Inclusion vulnerability | Holest Engineering | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | High | 7.5 | 2025-04-24 16:08:39 | Deep Dive |
| CVE-2025-21576 | Oracle Commerce 安全漏洞 | Oracle Corporation | Oracle Commerce Platform | Medium | 5.4 | 2025-04-15 20:30:54 | Deep Dive |
| CVE-2025-27190 | Adobe Commerce | Improper Access Control (CWE-284) | Adobe | Adobe Commerce | Medium | 5.3 | 2025-04-08 20:17:13 | Deep Dive |
| CVE-2025-27191 | Adobe Commerce | Improper Access Control (CWE-284) | Adobe | Adobe Commerce | Medium | 5.3 | 2025-04-08 20:17:11 | Deep Dive |
| CVE-2025-27192 | Adobe Commerce | Insufficiently Protected Credentials (CWE-522) | Adobe | Adobe Commerce | Low | 2.7 | 2025-04-08 20:17:11 | Deep Dive |
| CVE-2025-27188 | Adobe Commerce | Incorrect Authorization (CWE-863) | Adobe | Adobe Commerce | Medium | 4.3 | 2025-04-08 20:17:10 | Deep Dive |