Mercantec maintains a focused e-commerce platform product line centered on SoftCart, a shopping-cart solution with a narrow but established presence in the vulnerability record. The observed disclosures reflect input-handling and validation issues typical of web-facing transaction platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mercantec over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2221HIGH Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request. | Dec 31, 2004 | 7.5 | 55 | NO | YES |
CVE-1999-0609MEDIUM An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information. | Apr 1, 1999 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mercantec.
Media articles that mention a CVE ID that affects a product developed by Mercantec — matched by CVE ID, not by vendor name.