Expresscart
Vendor:
First CVE: Jun 7, 2018 · Active for 8 years
5
Total CVEs
Bottom 1%
1.7
Avg CVEs / Year
Bottom 1%
8.0
Avg CVSS
Higher Avg CVSS than 80% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Expresscart over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2018
8 years ago
Most Recent CVE
Aug 12, 2021
1,811 days ago
CVE Severity & Scoring
Expresscart5 CVEs
20%
80%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low3 (60.0%)
High1 (20.0%)
None1 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3758HIGH Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine. | Jun 7, 2018 | 8.8 | 41 | NO | NO |
CVE-2020-22403HIGH Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts. | Aug 12, 2021 | 8.8 | 26 | NO | NO |
CVE-2018-16483HIGH A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators. | Feb 1, 2019 | 8.8 | 25 | NO | NO |
CVE-2018-12457HIGH expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header. | Jun 15, 2018 | 8.8 | 25 | NO | NO |
CVE-2021-32573MEDIUM The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on | May 11, 2021 | 4.8 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Expresscart
Top CWEs
Versions
No cataloged versions.