Loadedcommerce develops Loaded 7, an e-commerce platform whose vulnerability profile centers on SQL injection—a critical input-handling weakness in web-facing database applications. This narrow vendor footprint reflects the platform's focused scope as a shopping-cart and catalog system. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Loadedcommerce over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5140HIGH The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated | Jan 3, 2020 | 8.8 | 38 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Loadedcommerce.
Media articles that mention a CVE ID that affects a product developed by Loadedcommerce — matched by CVE ID, not by vendor name.