Shopwind is a narrowly scoped e-commerce or content-management platform whose vulnerability profile concentrates in a single product line and centers on a durable pattern of web-application input-handling and access-control weaknesses including path traversal, cross-site scripting, code injection, and SQL injection. The vendor's vulnerabilities skew toward serious outcomes, reflecting the attack surface inherent to a web-facing application that processes user input and manages data access. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shopwind over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30453CRITICAL ShopWind <= 3.4.2 has a RCE vulnerability in Database.php | May 11, 2022 | 9.8 | 36 | NO | NO |
CVE-2022-43321MEDIUM Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php. | Nov 9, 2022 | 6.1 | 24 | NO | NO |
CVE-2022-30452HIGH ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php | May 11, 2022 | 7.2 | 23 | NO | NO |
CVE-2024-1705HIGH A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultControll | Feb 21, 2024 | 8.1 | 22 | NO | NO |
CVE-2022-30059MEDIUM Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php. | May 11, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-30058MEDIUM Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.php. | May 11, 2022 | 5.3 | 19 | NO | NO |
CVE-2022-30057MEDIUM Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability. | May 11, 2022 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shopwind.
Media articles that mention a CVE ID that affects a product developed by Shopwind — matched by CVE ID, not by vendor name.