Lockon maintains a narrowly focused product portfolio centered on EC-Cube, an e-commerce platform widely deployed in the Japanese market. Despite the vendor's modest disclosure volume, its prominence in the landscape reflects the widespread adoption and long operational lifetime of its primary product across retail deployments. The recurring vulnerability patterns cluster around web application input handling and session management: cross-site scripting and cross-site request forgery constitute the durable signal, alongside path traversal and information-disclosure flaws that are characteristic of legacy platform codebases. Defenders should prioritize tracking this vendor's updates for any EC-Cube installations in active use, given the product's exposure in customer-facing e-commerce environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lockon over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0808CRITICAL Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is explo | Jan 22, 2014 | 9.1 | 28 | NO | NO |
CVE-2013-3651HIGH LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and dat | Jun 30, 2013 | 7.5 | 26 | NO | NO |
CVE-2018-0564HIGH Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC- | Apr 20, 2018 | 8.1 | 24 | NO | NO |
CVE-2011-3988HIGH SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Oct 21, 2011 | 7.5 | 23 | NO | NO |
CVE-2016-1201HIGH Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the authentication of administrators. | Apr 30, 2016 | 8.8 | 22 | NO | NO |
CVE-2013-5993MEDIUM Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbitrary users via unspecified vect | Nov 21, 2013 | 6.8 | 22 | NO | NO |
CVE-2013-5995MEDIUM data/class/helper/SC_Helper_Address.php in the front-features implementation in LOCKON EC-CUBE 2.12.3 through 2.13.0 allows remote authenticated users to obtain sensitive informati | Nov 21, 2013 | 5.5 | 19 | NO | NO |
CVE-2011-1325MEDIUM Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | May 13, 2011 | 5.8 | 19 | NO | NO |
CVE-2016-1199MEDIUM The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via unspecified vectors, a differen | Apr 30, 2016 | 5.3 | 18 | NO | NO |
CVE-2013-5994MEDIUM data/class/pages/mypage/LC_Page_Mypage_DeliveryAddr.php in LOCKON EC-CUBE 2.11.2 through 2.13.0 allows remote attackers to obtain sensitive information via a direct request, which | Nov 21, 2013 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lockon.
Media articles that mention a CVE ID that affects a product developed by Lockon — matched by CVE ID, not by vendor name.