Shopxo is a small, modestly represented e-commerce platform whose vulnerability profile concentrates in a single product and skews strongly toward critical-severity outcomes. The recurring weakness classes—unrestricted file uploads, server-side request forgery, cross-site scripting, improper access control, and path traversal—reflect common attack patterns against web application frameworks and expose the product's web-facing architecture to direct compromise and lateral movement. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shopxo over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5108CRITICAL A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/controller/Payment.php of the compo | May 23, 2025 | 9.8 | 30 | NO | NO |
CVE-2021-27817CRITICAL A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying th | Mar 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-5886CRITICAL An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reins | Jan 10, 2019 | 9.8 | 30 | NO | NO |
CVE-2022-28056CRITICAL ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php. | May 2, 2022 | 9.8 | 29 | NO | NO |
CVE-2020-19778CRITICAL Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_id" in the HTML request. | Apr 14, 2021 | 9.8 | 28 | NO | NO |
CVE-2025-26325CRITICAL ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php. | Feb 27, 2025 | 9.8 | 26 | NO | NO |
CVE-2020-26008HIGH The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allows attackers to execute arbitra | Mar 20, 2022 | 7.8 | 26 | NO | NO |
CVE-2020-26007HIGH An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | Mar 20, 2022 | 7.8 | 26 | NO | NO |
CVE-2020-24220HIGH ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the server. | Aug 17, 2020 | 8.8 | 26 | NO | NO |
CVE-2024-6524HIGH A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. | Jul 5, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shopxo.
Media articles that mention a CVE ID that affects a product developed by Shopxo — matched by CVE ID, not by vendor name.