Shinecommerce operates through its Traveler product, a web-based application where the observed vulnerability pattern centers on input-handling and file-inclusion flaws characteristic of server-side web applications, including remote file inclusion and cross-site scripting weaknesses. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shinecommerce over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1771CRITICAL The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. | Mar 15, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-1773MEDIUM The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanit | Mar 15, 2025 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shinecommerce.
Media articles that mention a CVE ID that affects a product developed by Shinecommerce — matched by CVE ID, not by vendor name.