Leadshop is a narrowly scoped e-commerce and sales platform with a focused product footprint, presenting a contained but targeted attack surface. The recurring vulnerability signal reflects application-layer weaknesses including untrusted deserialization, exposed dangerous methods, and related implementation issues; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leadshop over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0739CRITICAL A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leadshop.php. The manipulation of th | Jan 19, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-4136CRITICAL Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host by calling any function in leadshop.php via the GET method. | Nov 24, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leadshop.
Media articles that mention a CVE ID that affects a product developed by Leadshop — matched by CVE ID, not by vendor name.