VYPR

Innoshop

by Innoshop

CVEs (2)

  • CVE-2025-52921CriJun 23, 2025
    risk 0.64cvss 9.9epss 0.00

    In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the…

  • CVE-2026-39250HigMay 19, 2026
    risk 0.47cvss 7.3epss 0.00

    An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfaces, leading to further dangerous operations.