Storecommander's vulnerability footprint is narrowly scoped to its e-commerce and accounting management products, such as Customers Export and QuickAccounting, with the observed exposure centered on database-interaction and access-control issues including SQL injection and incorrect default permissions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Storecommander over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33280CRITICAL In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blin | May 25, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-33278CRITICAL In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL inj | May 25, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-30281MEDIUM Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access | May 16, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Storecommander.
Media articles that mention a CVE ID that affects a product developed by Storecommander — matched by CVE ID, not by vendor name.