Implecode develops e-commerce product catalog and review management plugins that integrate with web-based shopping platforms, with vulnerabilities clustering around web application input handling and session management. The recurring weakness classes center on cross-site scripting, cross-site request forgery, and improper input validation—typical exposures for web-facing catalog and user-interaction components—alongside occasional information-disclosure risks. Defenders managing Implecode-based storefronts should prioritize input sanitization and CSRF protection in plugin deployments; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Implecode over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-52693CRITICAL Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. | Jun 15, 2026 | 9.3 | 34 | NO | NO |
CVE-2021-24875MEDIUM The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, lead | Nov 23, 2021 | 6.1 | 30 | NO | YES |
CVE-2026-57360HIGH Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions. | Jul 2, 2026 | 7.1 | 29 | NO | NO |
CVE-2021-24894MEDIUM The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when | Nov 23, 2021 | 6.5 | 23 | NO | NO |
CVE-2025-58992MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affe | Sep 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2023-51687HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode Product Catalog Simple.This issue affects Product Catalog Simple: from n/a through 1.7.6. | Dec 29, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-29388MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions. | Apr 7, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-49331HIGH Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue affects eCommerce Product Catalo | Jun 17, 2025 | 7.2 | 20 | NO | NO |
CVE-2024-32558HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog allows Reflected XSS.This issue affects eC | Apr 18, 2024 | 7.1 | 19 | NO | NO |
CVE-2023-51688HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Pl | Dec 29, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Implecode.
Media articles that mention a CVE ID that affects a product developed by Implecode — matched by CVE ID, not by vendor name.