Shopfiles develops a niche e-book retail platform that, despite modest disclosure volume, ranks among the more prominent in its category and has demonstrated an elevated tendency toward critical-severity vulnerabilities. The recurring exposure centers on its core e-book store product and clusters around input-handling and access-control weaknesses—namely cross-site scripting, sensitive information disclosure, and missing authorization—that are typical of web-facing retail applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shopfiles over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22701CRITICAL Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a th | Dec 9, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-8113MEDIUM The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross- | Aug 16, 2025 | 6.1 | 21 | NO | NO |
CVE-2023-45602MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.785 versions. | Oct 18, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-22690MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions. | May 15, 2023 | 4.8 | 19 | NO | NO |
CVE-2024-12262MEDIUM The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all versions up to, and including, 5.8001 due to insufficient input | Dec 21, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-11287MEDIUM The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, | Dec 21, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-6567MEDIUM The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not | Aug 2, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-23501MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Ebook Store allows Stored XSS.This issue affects Ebook Store: fr | Feb 29, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shopfiles.
Media articles that mention a CVE ID that affects a product developed by Shopfiles — matched by CVE ID, not by vendor name.