evershop CVE Vulnerabilities & Metrics

Focus on evershop vulnerabilities and metrics.

Last updated: 16 Jan 2026, 23:25 UTC

About evershop Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with evershop. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total evershop CVEs: 13
Earliest CVE date: 08 Dec 2023, 20:15 UTC
Latest CVE date: 05 Jan 2026, 20:16 UTC

Latest CVE reference: CVE-2025-67427

Rolling Stats

30-day Count (Rolling): 2
365-day Count (Rolling): 4

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical evershop CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.2

Max CVSS: 2.6

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS evershop CVEs

These are the five CVEs with the highest CVSS scores for evershop, sorted by severity first and recency.

All CVEs for evershop

CVE-2025-67427 evershop vulnerability CVSS: 0 05 Jan 2026, 20:16 UTC

A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET /images" API. The vulnerability occurs due to insufficient validation of the "src" query parameter, which permits arbitrary HTTP or HTTPS URIs, resulting in unexpected requests against internal and external networks.

CVE-2025-67419 evershop vulnerability CVSS: 0 05 Jan 2026, 20:16 UTC

A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles during the processing of SVG files, resulting in unbounded resource consumption and system-wide denial of service.

CVE-2025-65844 evershop vulnerability CVSS: 0 02 Dec 2025, 18:15 UTC

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentication by default, and server-side validation of uploaded files is insufficient. This can be abused to upload arbitrary content (including non-image files) which could impersonate user/admin login panels (exfiltrating credentials) and to perform a denial-of-service attack by exhausting disk space.

CVE-2025-12919 evershop vulnerability CVSS: 2.6 09 Nov 2025, 20:15 UTC

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-46943 evershop vulnerability CVSS: 0 13 Jan 2024, 02:15 UTC

An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.

CVE-2023-46942 evershop vulnerability CVSS: 0 13 Jan 2024, 02:15 UTC

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

CVE-2023-46499 evershop vulnerability CVSS: 0 08 Dec 2023, 20:15 UTC

Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel.

CVE-2023-46498 evershop vulnerability CVSS: 0 08 Dec 2023, 20:15 UTC

An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.

CVE-2023-46497 evershop vulnerability CVSS: 0 08 Dec 2023, 20:15 UTC

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the mkdirSync function in the folderCreate/createFolder.js endpoint.

CVE-2023-46496 evershop vulnerability CVSS: 0 08 Dec 2023, 20:15 UTC

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function in api/files endpoint.

CVE-2023-46495 evershop vulnerability CVSS: 0 08 Dec 2023, 20:15 UTC

Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the sortBy parameter.

CVE-2023-46494 evershop vulnerability CVSS: 0 08 Dec 2023, 20:15 UTC

Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted request to the ProductGrid function in admin/productGrid/Grid.jsx.

CVE-2023-46493 evershop vulnerability CVSS: 0 08 Dec 2023, 20:15 UTC

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the readDirSync function in fileBrowser/browser.js.