shopex CVE Vulnerabilities & Metrics

Focus on shopex vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About shopex Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with shopex. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total shopex CVEs: 13
Earliest CVE date: 25 May 2010, 14:30 UTC
Latest CVE date: 15 Feb 2024, 13:15 UTC

Latest CVE reference: CVE-2024-1530

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical shopex CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.88

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 8
7.0-8.9 5
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS shopex CVEs

These are the five CVEs with the highest CVSS scores for shopex, sorted by severity first and recency.

All CVEs for shopex

CVE-2024-1530 shopex vulnerability CVSS: 6.5 15 Feb 2024, 13:15 UTC

A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250562 is the identifier assigned to this vulnerability.

CVE-2023-5294 shopex vulnerability CVSS: 5.8 29 Sep 2023, 22:15 UTC

A vulnerability has been found in ECshop 4.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/order.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240925 was assigned to this vulnerability.

CVE-2023-5293 shopex vulnerability CVSS: 5.8 29 Sep 2023, 21:15 UTC

A vulnerability, which was classified as critical, was found in ECshop 4.1.5. Affected is an unknown function of the file /admin/leancloud.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240924.

CVE-2023-39112 shopex vulnerability CVSS: 0 04 Aug 2023, 17:15 UTC

ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.

CVE-2023-1185 shopex vulnerability CVSS: 5.8 06 Mar 2023, 08:15 UTC

A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222357 was assigned to this vulnerability.

CVE-2023-1184 shopex vulnerability CVSS: 5.8 06 Mar 2023, 08:15 UTC

A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of the file admin/database.php of the component Backup Database Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222356.

CVE-2023-0783 shopex vulnerability CVSS: 5.8 11 Feb 2023, 18:15 UTC

A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of the component PHP File Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220641 was assigned to this vulnerability.

CVE-2021-41460 shopex vulnerability CVSS: 5.0 28 Jun 2022, 13:15 UTC

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

CVE-2021-43679 shopex vulnerability CVSS: 7.5 02 Dec 2021, 15:15 UTC

ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.

CVE-2020-20640 shopex vulnerability CVSS: 4.3 28 Jun 2021, 18:15 UTC

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

CVE-2020-22206 shopex vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.

CVE-2020-22205 shopex vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.

CVE-2020-22204 shopex vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .

CVE-2010-2042 shopex vulnerability CVSS: 7.5 25 May 2010, 14:30 UTC

SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter. NOTE: some of these details are obtained from third party information.