Phoenixcart is an e-commerce platform vendor with a narrow product footprint centered on its CE Phoenix Cart shopping-cart application. Its durable vulnerability signal reflects web-application input handling and session-management weaknesses, including code injection, cross-site scripting, and improper cookie security controls that are characteristic of server-rendered commerce systems. Current severity, exploitation status, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phoenixcart over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25415HIGH A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload int | Feb 16, 2024 | 7.2 | 33 | NO | NO |
CVE-2025-47289CRITICAL CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attac | Jun 2, 2025 | 9.0 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phoenixcart.
Media articles that mention a CVE ID that affects a product developed by Phoenixcart — matched by CVE ID, not by vendor name.