Store Opart maintains a focused portfolio of commercial software products centered on quotation, proposal, and redirect management tools for small-to-medium business operations. The vulnerability disclosures associated with this vendor reflect its niche positioning and relatively limited installed base, with no prominent recurring weakness class emerging as a durable signal. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Store Opart over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48188CRITICAL SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a crafted script to the getModuleTranslation func | Nov 27, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-50061CRITICAL PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher(). | Feb 8, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-36263CRITICAL Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL c | Oct 31, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-34576CRITICAL SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector. | Sep 21, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-34575CRITICAL SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initConte | Sep 20, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-30148MEDIUM Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated u | Oct 14, 2023 | 5.4 | 18 | NO | NO |
CVE-2020-16194MEDIUM An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery a | Feb 4, 2021 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Store Opart.
Media articles that mention a CVE ID that affects a product developed by Store Opart — matched by CVE ID, not by vendor name.