All 2 CVE vulnerabilities found in e-shot, with AI-generated Chinese analysis, references, and POCs.
Vendor: forfront
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-3642 | e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX CWE-862 | 5.3 | Medium | 2026-04-15 |
| CVE-2026-3546 | e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX Action CWE-202 | 5.3 | Medium | 2026-03-21 |
All 2 known CVE vulnerabilities affecting e-shot with full Chinese analysis, references, and POCs where available.