Evershop is an open-source e-commerce platform whose vulnerability footprint centers on a single product but has achieved meaningful prominence in the landscape. The platform's disclosures skew strongly toward critical-severity outcomes and recur across a consistent set of structural weaknesses: path traversal and cross-site scripting vulnerabilities in web request handling, authorization bypass conditions tied to user-controlled access keys, resource exhaustion in loops, and exposure of sensitive data, which are characteristic of e-commerce applications handling authentication, payment workflows, and customer data. Defenders running Evershop-based storefronts should prioritize patch deployment for these input-handling and access-control classes; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evershop over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28213CRITICAL EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the | Feb 26, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-25993CRITICAL EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds
path / request_path values—derived from the url_key st | Feb 10, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-67419HIGH A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The ap | Jan 5, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-65844HIGH EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentica | Dec 2, 2025 | 7.5 | 25 | NO | NO |
CVE-2023-46498CRITICAL An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file. | Dec 8, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-46943CRITICAL An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses | Jan 13, 2024 | 9.1 | 24 | NO | NO |
CVE-2023-46496HIGH Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function | Dec 8, 2023 | 8.3 | 24 | NO | NO |
CVE-2025-67427MEDIUM A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET / | Jan 5, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-46942HIGH Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL | Jan 13, 2024 | 7.5 | 19 | NO | NO |
CVE-2023-46499MEDIUM Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel. | Dec 8, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evershop.
Media articles that mention a CVE ID that affects a product developed by Evershop — matched by CVE ID, not by vendor name.