Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

emarket-design — Vulnerabilities & Security Advisories 26

Browse all 26 CVE security advisories affecting emarket-design. AI-powered Chinese analysis, POCs, and references for each vulnerability.

emarket-design operates as a provider of e-commerce platform solutions, facilitating online retail operations for businesses. Security assessments have identified twenty-one distinct Common Vulnerabilities and Exposures (CVEs) associated with its software infrastructure. Historically, the most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from insufficient input validation and inadequate access controls within the application’s core modules. Notable security characteristics reveal a pattern of critical severity ratings, particularly in versions lacking recent patching. While specific major public incidents are not widely documented in open sources, the high volume of CVEs indicates systemic weaknesses in the development lifecycle. Organizations utilizing emarket-design solutions are advised to prioritize immediate patching of identified RCE and XSS vectors to mitigate potential exploitation risks.

CVE ID Title CVSS Severity Published
CVE-2026-15790 Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode — Video Gallery – YouTube Gallery, Playlist & Video Grid CWE-79 6.4 Medium 2026-08-16
CVE-2026-15011 Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter — Customer Support Ticket System & Helpdesk CWE-94 9.8 Critical 2026-07-23
CVE-2026-14249 Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter — Request a Quote – Quote Forms for Any WordPress Site CWE-74 7.5 High 2026-07-02
CVE-2026-12923 Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter — Video Gallery – YouTube Gallery, Playlist & Video Grid CWE-98 7.5 High 2026-07-01
CVE-2026-9848 WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter — Customer Support Ticket System & Helpdesk CWE-89 7.5 High 2026-06-13
CVE-2025-15636 WordPress YouTube Showcase plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability — YouTube Showcase CWE-79 6.5 Medium 2026-04-15
CVE-2025-64248 WordPress Request a Quote plugin <= 2.5.3 - Broken Access Control vulnerability — Request a Quote CWE-862 4.3 Medium 2025-12-16
CVE-2025-13403 Employee Spotlight – Team Member Showcase & Meet the Team Plugin <= 5.1.3 - Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification — Employee Spotlight – Team Member Showcase & Meet the Team Plugin CWE-862 4.3 Medium 2025-12-13
CVE-2025-12090 Employee Spotlight – Team Member Showcase & Meet the Team Plugin <= 5.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting — Employee Spotlight – Team Member Showcase & Meet the Team Plugin CWE-79 6.4 Medium 2025-11-01
CVE-2025-60157 WordPress WP Ticket Customer Service Software & Support Ticket System Plugin <= 6.0.2 - Cross Site Scripting (XSS) Vulnerability — WP Ticket Customer Service Software & Support Ticket System CWE-79 6.5 Medium 2025-09-26
CVE-2025-58915 WordPress Request a Quote plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability — Request a Quote CWE-79 6.5 Medium 2025-09-23
CVE-2025-54731 WordPress YouTube Showcase Plugin <= 3.5.1 - PHP Object Injection Vulnerability — YouTube Showcase CWE-94 8.1 High 2025-08-28
CVE-2025-53584 WordPress WP Ticket Customer Service Software & Support Ticket System Plugin <= 6.0.2 - PHP Object Injection Vulnerability — WP Ticket Customer Service Software & Support Ticket System CWE-502 8.1 High 2025-08-28
CVE-2025-53583 WordPress Employee Spotlight Plugin <= 5.1.1 - PHP Object Injection Vulnerability — Employee Spotlight CWE-502 8.1 High 2025-08-28
CVE-2025-53572 WordPress WP Easy Contact Plugin <= 4.0.1 - PHP Object Injection Vulnerability — WP Easy Contact CWE-502 8.1 High 2025-08-28
CVE-2025-53243 WordPress Employee Directory – Staff Listing & Team Directory plugin for WordPress plugin <= 4.5.5 - PHP Object Injection vulnerability — Employee Directory – Staff Listing & Team Directory Plugin for WordPress CWE-502 8.1 High 2025-08-28
CVE-2025-8314 Software Issue Manager <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess_msg Parameter — Project Management, Bug and Issue Tracking Plugin – Software Issue Manager CWE-79 6.4 Medium 2025-08-12
CVE-2025-8420 Multiple Plugins by emarket-design <= Multiple Versions - Unauthenticated Limited Remote Code Execution — Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress CWE-95 8.1 High 2025-08-06
CVE-2025-8295 Employee Directory <= 4.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess_msg Parameter — Employee Directory – Staff & Team Directory CWE-79 6.4 Medium 2025-08-05
CVE-2025-8313 Campus Directory <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess_msg Parameter — Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress CWE-79 6.4 Medium 2025-08-05
CVE-2025-8315 WP Easy Contact <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess_msg Parameter — Simple Contact Form Plugin for WordPress – WP Easy Contact CWE-79 6.4 Medium 2025-08-05
CVE-2025-5540 Event RSVP and Simple Event Management Plugin <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — Event RSVP and Simple Event Management Plugin CWE-79 6.4 Medium 2025-06-26
CVE-2025-5539 Simplify Contact Management: WP Easy Contact <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — Simple Contact Form Plugin for WordPress – WP Easy Contact CWE-79 6.4 Medium 2025-06-04
CVE-2025-5532 Faculty Staff and Student Directory Plugin – Campus Directory <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress CWE-79 6.4 Medium 2025-06-04
CVE-2025-5531 Staff Directory – Employee Directory for WordPress <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — Employee Directory – Staff & Team Directory CWE-79 6.4 Medium 2025-06-04
CVE-2024-3268 YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation — Video Gallery – YouTube Gallery & Responsive Video Playlist CWE-862 5.3 Medium 2024-05-21

This page lists every published CVE security advisory associated with emarket-design. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.