cs-cart CVE Vulnerabilities & Metrics

Focus on cs-cart vulnerabilities and metrics.

Last updated: 27 Apr 2025, 22:25 UTC

About cs-cart Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with cs-cart. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total cs-cart CVEs: 12
Earliest CVE date: 21 Dec 2005, 00:03 UTC
Latest CVE date: 25 Sep 2024, 01:15 UTC

Latest CVE reference: CVE-2023-26691

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 6

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical cs-cart CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.39

Max CVSS: 9.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 9
7.0-8.9 4
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS cs-cart CVEs

These are the five CVEs with the highest CVSS scores for cs-cart, sorted by severity first and recency.

All CVEs for cs-cart

CVE-2023-26691 cs-cart vulnerability CVSS: 0 25 Sep 2024, 01:15 UTC

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.

CVE-2023-26690 cs-cart vulnerability CVSS: 0 25 Sep 2024, 01:15 UTC

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.

CVE-2023-26689 cs-cart vulnerability CVSS: 0 25 Sep 2024, 01:15 UTC

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVE-2023-26688 cs-cart vulnerability CVSS: 0 25 Sep 2024, 01:15 UTC

Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.

CVE-2023-26687 cs-cart vulnerability CVSS: 0 25 Sep 2024, 01:15 UTC

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.

CVE-2023-26686 cs-cart vulnerability CVSS: 0 25 Sep 2024, 01:15 UTC

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.

CVE-2021-32202 cs-cart vulnerability CVSS: 4.3 14 Sep 2021, 12:15 UTC

In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page.

CVE-2017-15673 cs-cart vulnerability CVSS: 9.0 28 Nov 2017, 15:29 UTC

The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.

CVE-2017-10886 cs-cart vulnerability CVSS: 3.5 17 Nov 2017, 14:29 UTC

Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

CVE-2017-2138 cs-cart vulnerability CVSS: 6.8 02 Aug 2017, 16:29 UTC

Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4862 cs-cart vulnerability CVSS: 6.5 20 Apr 2017, 18:59 UTC

Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.

CVE-2015-2701 cs-cart vulnerability CVSS: 6.8 25 Mar 2015, 14:59 UTC

Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/.

CVE-2013-7317 cs-cart vulnerability CVSS: 4.3 24 Jan 2014, 15:08 UTC

Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) settings_file or (2) data_file parameter to (a) ampie.swf, (b) amline.swf, or (c) amcolumn.swf.

CVE-2013-0118 cs-cart vulnerability CVSS: 5.0 24 Feb 2013, 11:48 UTC

CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.

CVE-2009-4891 cs-cart vulnerability CVSS: 7.5 11 Jun 2010, 14:30 UTC

SQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a products.view action.

CVE-2009-2579 cs-cart vulnerability CVSS: 6.5 05 Aug 2009, 19:30 UTC

SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.

CVE-2008-6394 cs-cart vulnerability CVSS: 7.5 04 Mar 2009, 17:30 UTC

SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.

CVE-2008-1458 cs-cart vulnerability CVSS: 4.3 24 Mar 2008, 18:44 UTC

Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action. NOTE: it was also reported that 1.3.5-SP2 trial edition is also affected.

CVE-2007-0230 cs-cart vulnerability CVSS: 7.5 13 Jan 2007, 02:28 UTC

PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter. NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use

CVE-2006-2863 cs-cart vulnerability CVSS: 5.1 06 Jun 2006, 20:06 UTC

PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.

CVE-2005-4429 cs-cart vulnerability CVSS: 7.5 21 Dec 2005, 00:03 UTC

SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.