S Cart is an open-source e-commerce platform with a focused vulnerability footprint around its core shopping-cart and storefront application. The observed disclosures reflect typical application-level exposure patterns for web-based commerce systems. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by S Cart over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-7012HIGH scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter of a show_text action. | Feb 15, 2007 | 10.0 | 36 | NO | YES |
CVE-2021-38847HIGH S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Admin panel. This vulnerability allows attackers to execute arb | Nov 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-28456MEDIUM The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel. | Dec 15, 2020 | 6.1 | 20 | NO | NO |
The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits th | May 1, 2022 | 3.5 | 17 | NO | NO |
CVE-2021-44111MEDIUM A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup. | Feb 11, 2022 | 4.4 | 17 | NO | NO |
CVE-2020-28457MEDIUM This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS. | Dec 15, 2020 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by S Cart.
Media articles that mention a CVE ID that affects a product developed by S Cart — matched by CVE ID, not by vendor name.