Shop Beat Solutions develops a focused media-player product whose vulnerability profile skews strongly toward critical-severity outcomes and concentrates on access-control and input-handling weaknesses. The recurring issues—authentication bypass, authorization bypass through user-controlled keys, cross-site request forgery, directory listing exposure, and path traversal—reflect common deficiencies in web and application-layer security controls that can grant attackers unauthorized access to functionality or sensitive data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shop Beat Solutions (Pty) LTD over time
Of all the CVEs published by Shop Beat Solutions (Pty) LTD as a CNA, 100.0% affect products that Shop Beat Solutions (Pty) LTD develops as a vendor.
Of all the CVEs published that affect products developed by Shop Beat Solutions (Pty) LTD, 100.0% are self-published by Shop Beat Solutions (Pty) LTD as a CNA.
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36246CRITICAL Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions. | May 30, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-36247CRITICAL Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za. | May 30, 2023 | 9.1 | 26 | NO | NO |
CVE-2022-36250HIGH Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Cross Site Request Forgery (CSRF). | May 30, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-36249MEDIUM Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the b | May 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2022-36244MEDIUM Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found a | May 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2022-36243MEDIUM Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory List | May 30, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shop Beat Solutions (Pty) LTD.
Media articles that mention a CVE ID that affects a product developed by Shop Beat Solutions (Pty) LTD — matched by CVE ID, not by vendor name.