Common Services maintains a narrow portfolio of specialized logistics and fulfillment software products, including SO Flexibilité, SO Liberté, and SO Nice labeling and return-management tools, which serve focused operational niches. The durable signal across this vendor centers on the specificity of its product line rather than broad patterns in weakness classes. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Common Services over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40921CRITICAL SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters. | Dec 14, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-45382HIGH In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a | Nov 17, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-45383HIGH In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by perf | Oct 18, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-25844HIGH An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain s | Mar 3, 2024 | 7.5 | 19 | NO | NO |
CVE-2024-25841MEDIUM In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection. | Feb 27, 2024 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Common Services.
Media articles that mention a CVE ID that affects a product developed by Common Services — matched by CVE ID, not by vendor name.