Litecart is a niche e-commerce platform whose vulnerability profile centers on its single core product and recurs through application-layer input-handling issues spanning cross-site scripting, cross-site request forgery, and unsafe file-upload handling. The exposure also reflects data-generation and resource-consumption weaknesses common to shopping-cart and administrative interfaces. Treat this as a focused vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Litecart over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12256HIGH admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml | Aug 16, 2018 | 8.8 | 28 | NO | NO |
CVE-2020-9017HIGH LiteCart through 2.2.1 allows CSV injection via a customer's profile. | Feb 25, 2020 | 8.0 | 25 | NO | NO |
CVE-2018-10827HIGH LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bou | May 9, 2018 | 7.5 | 23 | NO | NO |
CVE-2022-27168MEDIUM Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary script via unspecified vectors. | Jul 11, 2022 | 6.1 | 22 | NO | NO |
CVE-2020-9018MEDIUM LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user. | Feb 25, 2020 | 5.3 | 19 | NO | NO |
CVE-2014-7183MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) quer | Oct 22, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Litecart.
Media articles that mention a CVE ID that affects a product developed by Litecart — matched by CVE ID, not by vendor name.