Ecshop is a narrowly scoped e-commerce platform product with a durable vulnerability signal centered on SQL injection flaws in its query-handling logic. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecshop over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3412HIGH SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) dispp | Jul 31, 2008 | 7.5 | 29 | NO | YES |
CVE-2009-1622HIGH SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action. | May 12, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecshop.
Media articles that mention a CVE ID that affects a product developed by Ecshop — matched by CVE ID, not by vendor name.