Fishnet operates a focused e-commerce platform (Fishcart) with a narrow but above-typical vulnerability footprint, characterized by application-layer input-handling weaknesses including cross-site scripting, SQL injection, and other web-facing flaws. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fishnet over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1487HIGH Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to | May 11, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-1486MEDIUM Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m paramete | May 11, 2005 | 5.0 | 25 | NO | YES |
CVE-2004-0062HIGH Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large qu | Feb 17, 2004 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fishnet.
Media articles that mention a CVE ID that affects a product developed by Fishnet — matched by CVE ID, not by vendor name.