CS Cart is an e-commerce platform and marketplace software used to power online storefronts and multi-vendor selling environments. The vendor's vulnerability portfolio, though modest in scale, reflects the attack surface inherent to web-based commerce applications handling customer data, payment processing, and administrative workflows. Recurring exposures cluster around its flagship CS Cart and CS Cart MultiVendor products, though specific weakness patterns have not yet established a durable profile across the disclosed vulnerabilities. Defenders deploying this platform should maintain current patch levels and monitor vendor advisories for application-layer risks typical of web commerce systems; current exposure counts and vulnerability severity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cs Cart over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26686CRITICAL File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop. | Sep 25, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-50850HIGH An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an att | Jul 31, 2025 | 8.6 | 29 | NO | NO |
CVE-2023-26689CRITICAL An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request. | Sep 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2008-6394HIGH SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie para | Mar 4, 2009 | 7.5 | 28 | NO | YES |
CVE-2005-4429HIGH SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php. | Dec 21, 2005 | 7.5 | 28 | NO | YES |
CVE-2016-4862HIGH Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the s | Apr 20, 2017 | 8.8 | 27 | NO | NO |
CVE-2015-2701MEDIUM Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a reques | Mar 25, 2015 | 6.8 | 27 | NO | YES |
CVE-2023-26690HIGH File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu. | Sep 25, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-26687HIGH Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on. | Sep 25, 2024 | 8.8 | 26 | NO | NO |
CVE-2017-2138HIGH Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (exc | Aug 2, 2017 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cs Cart.
Media articles that mention a CVE ID that affects a product developed by Cs Cart — matched by CVE ID, not by vendor name.