Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cs Cart

First CVE: Dec 21, 2005Active for: 21 yearsTotal CVEs: 48

CS Cart is an e-commerce platform and marketplace software used to power online storefronts and multi-vendor selling environments. The vendor's vulnerability portfolio, though modest in scale, reflects the attack surface inherent to web-based commerce applications handling customer data, payment processing, and administrative workflows. Recurring exposures cluster around its flagship CS Cart and CS Cart MultiVendor products, though specific weakness patterns have not yet established a durable profile across the disclosed vulnerabilities. Defenders deploying this platform should maintain current patch levels and monitor vendor advisories for application-layer risks typical of web commerce systems; current exposure counts and vulnerability severity are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cs Cart over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2005
20 years ago
Most Recent CVE
Jul 31, 2025
358 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-26686CRITICAL
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.
Sep 25, 20249.830NONO
CVE-2025-50850HIGH
An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an att
Jul 31, 20258.629NONO
CVE-2023-26689CRITICAL
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
Sep 25, 20249.829NONO
CVE-2008-6394HIGH
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie para
Mar 4, 20097.528NOYES
CVE-2005-4429HIGH
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
Dec 21, 20057.528NOYES
CVE-2016-4862HIGH
Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the s
Apr 20, 20178.827NONO
CVE-2015-2701MEDIUM
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a reques
Mar 25, 20156.827NOYES
CVE-2023-26690HIGH
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.
Sep 25, 20248.826NONO
CVE-2023-26687HIGH
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.
Sep 25, 20248.826NONO
CVE-2017-2138HIGH
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (exc
Aug 2, 20178.826NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
46%
46%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (58.3%)
Unknown10 (41.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (58.3%)
High0 (0.0%)
Unknown10 (41.7%)
User Interaction
None9 (37.5%)
Unknown10 (41.7%)
Required5 (20.8%)
Privileges Required
Low5 (20.8%)
High2 (8.3%)
None7 (29.2%)
Unknown10 (41.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cs Cart.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cs Cart — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cs Cart's Products

View all 3 CNAs →

Top CWEs