Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Abantecart

First CVE: Mar 21, 2019Active for: 7 yearsTotal CVEs: 11
35.6
VTI Score
Medium

Abantecart is a modestly represented e-commerce platform with a concentrated vulnerability footprint centered on its core storefront product. Its disclosures cluster around common web-application input-handling and file-management weaknesses—cross-site scripting, SQL injection, path traversal, and unrestricted file upload—that reflect the typical attack surface of customer-facing shopping applications. A meaningful share of its vulnerabilities reach serious severity, and the platform's public-facing role has made exploit code available for some issues; live exploitation activity and current counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Abantecart over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2019
7 years ago
Most Recent CVE
Aug 27, 2025
331 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-50972CRITICAL
SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index.php. Three techniques have be
Aug 27, 20259.831NONO
CVE-2022-26521HIGH
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can
Mar 10, 20227.231NOYES
CVE-2016-10755HIGH
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to a
May 24, 20198.828NONO
CVE-2025-50971HIGH
Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.
Aug 26, 20257.525NONO
CVE-2021-42050MEDIUM
An issue was discovered in AbanteCart before 1.3.2. It allows DOM Based XSS.
Dec 14, 20216.122NONO
CVE-2021-42051MEDIUM
An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload.
Dec 14, 20215.419NONO
CVE-2018-20141MEDIUM
AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring.
Mar 21, 20196.119NONO
CVE-2025-40627MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim a malic
May 12, 20256.118NONO
CVE-2024-50802MEDIUM
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerabil
Oct 31, 20246.018NONO
CVE-2024-50801MEDIUM
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability
Oct 31, 20246.018NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
27%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low2 (18.2%)
High3 (27.3%)
None6 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Abantecart.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Abantecart — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Abantecart's Products

View all 2 CNAs →

Top CWEs