sparkshop
by sparkshop
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-50722 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2025 | Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component | ||
| CVE-2024-40425 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component. | ||
| CVE-2024-46307 | Hig | 0.49 | 7.5 | 0.00 | Oct 9, 2024 | A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products. | ||
| CVE-2024-48107 | Med | 0.42 | 6.5 | 0.00 | Oct 28, 2024 | SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server. | ||
| CVE-2024-57685 | Med | 0.34 | 5.3 | 0.00 | Feb 24, 2025 | An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file. |
- risk 0.64cvss 9.8epss 0.01
Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component.
- risk 0.49cvss 7.5epss 0.00
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
- risk 0.42cvss 6.5epss 0.00
SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server.
- risk 0.34cvss 5.3epss 0.00
An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.