Proticaret operates a focused e-commerce or web-based platform product, with its vulnerability profile centered on application-layer input handling and session management. The recurring exposure involves cross-site request forgery and SQL injection weaknesses, both characteristic of web applications where request validation and parameterized query discipline are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Proticaret over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9237HIGH SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP request. | Dec 3, 2014 | 7.5 | 28 | NO | YES |
CVE-2024-11142HIGH Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forgery.
This issue affects Proticaret E-Commerce: before v6.0
| May 2, 2025 | 8.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Proticaret.
Media articles that mention a CVE ID that affects a product developed by Proticaret — matched by CVE ID, not by vendor name.