Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-72843
EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account Takeover
CVE-2026-28213
EverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset Token in API Response
CVE-2026-25993
EverShop has a Second-Order SQL Injection in URL Rewrite Processing Derived from Category URL Keys
CVE-2025-67419
A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles during the processing of SVG files, resulting in unbounded resource consumption and system-wide denial of service.
CVE-2025-67427
A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET /images" API. The vulnerability occurs due to insufficient validation of the "src" query parameter, which permits arbitrary HTTP or HTTPS URIs, resulting in unexpected requests against internal and external networks.
