Abantecart is a modestly represented e-commerce platform with a concentrated vulnerability footprint centered on its core storefront product. Its disclosures cluster around common web-application input-handling and file-management weaknesses—cross-site scripting, SQL injection, path traversal, and unrestricted file upload—that reflect the typical attack surface of customer-facing shopping applications. A meaningful share of its vulnerabilities reach serious severity, and the platform's public-facing role has made exploit code available for some issues; live exploitation activity and current counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Abantecart over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50972CRITICAL SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index.php. Three techniques have be | Aug 27, 2025 | 9.8 | 31 | NO | NO |
CVE-2022-26521HIGH Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can | Mar 10, 2022 | 7.2 | 31 | NO | YES |
CVE-2016-10755HIGH AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to a | May 24, 2019 | 8.8 | 28 | NO | NO |
CVE-2025-50971HIGH Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php. | Aug 26, 2025 | 7.5 | 25 | NO | NO |
CVE-2021-42050MEDIUM An issue was discovered in AbanteCart before 1.3.2. It allows DOM Based XSS. | Dec 14, 2021 | 6.1 | 22 | NO | NO |
CVE-2021-42051MEDIUM An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload. | Dec 14, 2021 | 5.4 | 19 | NO | NO |
CVE-2018-20141MEDIUM AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring. | Mar 21, 2019 | 6.1 | 19 | NO | NO |
CVE-2025-40627MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim a malic | May 12, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-50802MEDIUM A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerabil | Oct 31, 2024 | 6.0 | 18 | NO | NO |
CVE-2024-50801MEDIUM A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability | Oct 31, 2024 | 6.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Abantecart.
Media articles that mention a CVE ID that affects a product developed by Abantecart — matched by CVE ID, not by vendor name.