Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-28213 EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifyi… Evershop 2.1.1+ Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2026-25993 EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path val… Evershop after 2.1.0 Fix from $2,3002026-02-10 HIGH 7.5 CVE-2025-67419 A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources vi… Evershop after 2.1.0 Fix from $1,9502026-01-05 MEDIUM 6.5 CVE-2025-67427 A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate… Evershop after 2.1.0 Fix from $1,6002026-01-05 HIGH 7.5 CVE-2025-65844 EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint i… Evershop No fix yet Fix from $1,9502025-12-02 CRITICAL 9.1 CVE-2023-46943 An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "se… Evershop Mitigation only Fix from $2,3002024-01-13 HIGH 7.5 CVE-2023-46942 Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via imp… Evershop Mitigation only Fix from $1,9502024-01-13 CRITICAL 9.8 CVE-2023-46498 An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /de… Evershop Mitigation only Fix from $2,3002023-12-08 HIGH 8.3 CVE-2023-46496 Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted… Evershop Mitigation only Fix from $1,9502023-12-08 MEDIUM 6.1 CVE-2023-46494 Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafte… Evershop Mitigation only Fix from $1,6002023-12-08 MEDIUM 6.1 CVE-2023-46495 Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafte… Evershop Mitigation only Fix from $1,6002023-12-08 MEDIUM 6.1 CVE-2023-46499 Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafte… Evershop Mitigation only Fix from $1,6002023-12-08 MEDIUM 5.4 CVE-2023-46497 Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted… Evershop Mitigation only Fix from $1,6002023-12-08 MEDIUM 5.3 CVE-2023-46493 Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted… Evershop Mitigation only Fix from $1,6002023-12-08