Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Litecart

First CVE: Oct 22, 2014Active for: 12 yearsTotal CVEs: 6

Litecart is a niche e-commerce platform whose vulnerability profile centers on its single core product and recurs through application-layer input-handling issues spanning cross-site scripting, cross-site request forgery, and unsafe file-upload handling. The exposure also reflects data-generation and resource-consumption weaknesses common to shopping-cart and administrative interfaces. Treat this as a focused vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Litecart over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 22, 2014
11 years ago
Most Recent CVE
Jul 11, 2022
1,474 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-12256HIGH
admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml
Aug 16, 20188.828NONO
CVE-2020-9017HIGH
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
Feb 25, 20208.025NONO
CVE-2018-10827HIGH
LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bou
May 9, 20187.523NONO
CVE-2022-27168MEDIUM
Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
Jul 11, 20226.122NONO
CVE-2020-9018MEDIUM
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
Feb 25, 20205.319NONO
CVE-2014-7183MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) quer
Oct 22, 20144.314NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (83.3%)
Unknown1 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High0 (0.0%)
Unknown1 (16.7%)
User Interaction
None3 (50.0%)
Unknown1 (16.7%)
Required2 (33.3%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None3 (50.0%)
Unknown1 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Litecart.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Litecart — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Litecart's Products

View all 2 CNAs →

Top CWEs