Sparkshop's vulnerability footprint centers on its core e-commerce and marketplace platform, where reported issues cluster around input-handling and workflow-control weaknesses including command injection, server-side request forgery, and unrestricted file uploads. These patterns reflect risks typical of web-facing retail and vendor-management applications that process user input and handle file storage. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sparkshop over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50722CRITICAL Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component | Aug 25, 2025 | 9.8 | 31 | NO | NO |
CVE-2024-40425CRITICAL File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller | Jul 16, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-46307HIGH A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products. | Oct 9, 2024 | 7.5 | 25 | NO | NO |
CVE-2024-48107MEDIUM SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, at | Oct 28, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-57685MEDIUM An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file. | Feb 24, 2025 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sparkshop.
Media articles that mention a CVE ID that affects a product developed by Sparkshop — matched by CVE ID, not by vendor name.