Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Welcart e-Commerce — Vulnerabilities & Security Advisories 46

All 46 CVE vulnerabilities found in Welcart e-Commerce, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting the Welcart e-Commerce product. It collects various weakness types, including SQL injection, cross-site scripting, and path traversal, covering advisories published over the recent years. You can use this section to track vendor security advisories, understand the impact of specific weakness classes, and review the complete vulnerability history for this product. The data provides a structured view of how vulnerabilities evolve across different versions, enabling users to identify recurring patterns and assess remediation needs. No specific CVE identifiers are listed here; instead, the focus is on categorizing issues by type and timeframe. This aggregation helps developers and security teams monitor the security posture of the Welcart e-Commerce platform and prioritize fixes based on severity and frequency of occurrences.

Vendor: Collne Inc.

CVE ID Title CVSS Severity Published
CVE-2023-43493 WordPress Plugin Welcart e-Commerce SQL注入漏洞 6.5 - 2023-09-26
CVE-2023-43484 WordPress Plugin Welcart e-Commerce 跨站脚本漏洞 6.1 - 2023-09-26
CVE-2023-41962 WordPress plugin Welcart e-Commerce 安全漏洞 6.1 - 2023-09-26
CVE-2023-41233 WordPress plugin Welcart e-Commerce 跨站脚本漏洞 6.1 - 2023-09-26
CVE-2023-40532 WordPress plugin Welcart e-Commerce 路径遍历漏洞 4.3 - 2023-09-26
CVE-2023-40219 WordPress plugin Welcart e-Commerce 代码问题漏洞 8.8 - 2023-09-26
CVE-2021-4375 Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure CWE-862 4.3 Medium 2023-06-07
CVE-2021-4355 Welcart e-Commerce < 2.2.8 - Missing Capabilities Check to Information Disclosure CWE-862 7.5 High 2023-06-07
CVE-2023-22705 WordPress Welcart e-Commerce Plugin <= 2.8.10 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-03-29
CVE-2022-4655 Welcart e-Commerce < 2.8.9 - Contributor+ Stored XSS via Shortcode 5.4 - 2023-01-16
CVE-2022-4237 Welcart e-Commerce < 2.8.6 - Subscriber+ PHAR Deserialisation 8.8 - 2023-01-02
CVE-2022-4236 Welcart e-Commerce < 2.8.5 - Subscriber+ Arbitrary File Access 6.5 - 2023-01-02
CVE-2022-4140 Welcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File Access 7.5 - 2023-01-02
CVE-2022-3946 Welcart e-Commerce < 2.8.4 - Subscriber+ Arbitrary Shipping Method Creation/Update/Deletion 6.5 - 2022-12-12
CVE-2022-3935 Welcart e-Commerce < 2.8.4 - Multiple Subscriber+ Stored Cross-Site Scripting 5.4 - 2022-12-12
CVE-2021-20734 WordPress 跨站脚本漏洞 6.1 - 2021-06-22

All 46 known CVE vulnerabilities affecting Welcart e-Commerce with full Chinese analysis, references, and POCs where available.