Cfshopkart is a small e-commerce platform vendor centered on its cf_shopkart shopping cart application, which handles customer transactional workflows and data processing. The recurring vulnerability signal reflects application-layer input-handling weaknesses, specifically SQL injection, which is typical of web-facing commerce systems that interface with backend databases. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cfshopkart over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3309HIGH SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a diffe | Sep 23, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6320HIGH SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands via the Category parameter in a ViewCategory action. | Feb 27, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6321MEDIUM CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information, such as usernames and | Feb 27, 2009 | 5.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cfshopkart.
Media articles that mention a CVE ID that affects a product developed by Cfshopkart — matched by CVE ID, not by vendor name.