Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Shopping Cart & eCommerce Store — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Shopping Cart & eCommerce Store, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting the Shopping Cart and eCommerce Store product category, focusing on common weakness types and vendor advisories. It collects data on identified security flaws, ranging from code injection and cross-site scripting to insecure direct object references, covering reports issued from 2015 through the present. The collected data represents a comprehensive view of the security landscape for major platforms, including widely used open-source solutions and proprietary enterprise systems that facilitate online transactions. Here, you can track a vendor's advisories to monitor how specific providers respond to critical flaws in their software suites. You can also understand a weakness class by analyzing trends across multiple implementations to determine which coding errors are most prevalent in this sector. Additionally, you can look up a product's vulnerability history to assess the long-term security posture of an eCommerce engine before making adoption decisions. This resource is designed for security analysts, developers, and procurement officers who need factual, historical context about software risks. By reviewing these aggregated entries, stakeholders can better evaluate the maturity of a vendor’s patching process and the consistency of their security updates. The goal is to provide a clear, neutral overview of the risks associated with online store infrastructure without promoting any specific solution. This aggregation serves as a reference point for understanding the common attack surfaces inherent in shopping cart software.

Vendor: WP EasyCart

CVE IDTitleCVSSSeverityPublished
CVE-2024-12712 Shopping Cart & eCommerce Store <= 5.7.8 - Missing Authorization to Order Updates CWE-862 5.3 Medium2025-01-08
CVE-2024-7827 Shopping Cart & eCommerce Store <= 5.7.2 - Authenticated (Contributor+) SQL Injection via model_number Parameter CWE-89 8.8 High2024-08-20
CVE-2024-4213 Shopping Cart & eCommerce Store <= 5.6.4 - Sensitive Information Exposure CWE-922 5.3 Medium2024-05-10
CVE-2024-3211 Shopping Cart & eCommerce Store <= 5.6.3 - Authenticated (Contributor+) SQL Injection CWE-89 8.8 High2024-04-12
CVE-2023-3023 WP EasyCart <= 5.4.10 - Authenticated (Administrator+) SQL Injection via 'orderby' CWE-89 7.2 High2023-07-12
CVE-2023-2892 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_delete_product CWE-352 6.5 Medium2023-06-09
CVE-2023-2894 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_deactivate_product CWE-352 4.3 Medium2023-06-09
CVE-2023-2893 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_deactivate_product CWE-352 4.3 Medium2023-06-09
CVE-2023-2896 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_duplicate_product CWE-352 4.3 Medium2023-06-09
CVE-2023-2895 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_activate_product CWE-352 4.3 Medium2023-06-09
CVE-2023-2891 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_delete_product CWE-352 6.5 Medium2023-06-09
CVE-2023-1124 Shopping Cart & eCommerce Store < 5.4.3 - Admin+ LFI 7.2 -2023-04-03
CVE-2021-34645 Shopping Cart & eCommerce Store <= 5.1.0 Cross-Site Request Forgery to Stored Cross-Site Scripting CWE-352 8.8 High2021-08-19

All 13 known CVE vulnerabilities affecting Shopping Cart & eCommerce Store with full Chinese analysis, references, and POCs where available.