VYPR
Vendor

Spa Cart

Products
3
CVEs
7
Across products
9
Status
Private

Products

3

Recent CVEs

7
  • CVE-2023-43149HigOct 12, 2023
    risk 0.57cvss 8.8epss 0.01

    SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status.

  • CVE-2023-43148HigOct 12, 2023
    risk 0.53cvss 8.1epss 0.00

    SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.

  • CVE-2023-4548MedAug 26, 2023
    risk 0.46cvss 6.3epss 0.32

    A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from…

  • CVE-2024-58304MedDec 11, 2025
    risk 0.40cvss 6.1epss 0.00

    SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit…

  • CVE-2024-6128MedJun 18, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of…

  • CVE-2023-4547LowAug 26, 2023
    risk 0.31cvss 3.5epss 0.60

    A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit…

  • CVE-2024-6129LowJun 18, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username Handler. The manipulation of the argument email leads to observable behavioral discrepancy. It is possible to…