EC-Cube is a Japanese e-commerce platform and point-of-sale system with a modest but distributed vulnerability footprint concentrated in its core framework and payment processing modules. The vendor's exposure spans the main EC-Cube platform along with ancillary components such as business form output, payment modules, and logistics-integration features that are characteristic of a comprehensive cart and order-management suite. Weakness patterns across its disclosures have not coalesced into a clearly defined durable class, reflecting the fragmented nature of a modestly represented vendor in the landscape. Defenders maintaining or hosting EC-Cube deployments should monitor vendor security advisories closely, particularly around payment and order-handling components; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ec Cube over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4837CRITICAL SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Aug 1, 2016 | 9.8 | 31 | NO | NO |
CVE-2022-37346CRITICAL EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a r | Sep 27, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-5680HIGH Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector. | Dec 3, 2020 | 7.5 | 24 | NO | NO |
CVE-2018-0658HIGH Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) version 2.3.17 and earlier, GMO-PG Payment Module (PG Multi-Paymen | Sep 7, 2018 | 7.2 | 24 | NO | NO |
CVE-2026-30777MEDIUM EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be ab | Mar 5, 2026 | 6.5 | 23 | NO | NO |
CVE-2021-20842MEDIUM Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator | Nov 24, 2021 | 6.5 | 23 | NO | NO |
CVE-2021-20841MEDIUM Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access restriction and to alter System settings v | Nov 24, 2021 | 6.5 | 23 | NO | NO |
CVE-2021-20778HIGH Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vec | Jul 1, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-20717MEDIUM Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is c | May 10, 2021 | 6.1 | 22 | NO | NO |
CVE-2021-20828MEDIUM Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified | Sep 17, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ec Cube.
Media articles that mention a CVE ID that affects a product developed by Ec Cube — matched by CVE ID, not by vendor name.