Sunshinephotocart's vulnerability profile centers on its photo-cart e-commerce product, which features a pattern of authentication and input-handling weaknesses including missing authorization, CSRF, cross-site scripting, deserialization flaws, and authorization-bypass conditions. Vulnerabilities affecting this vendor skew toward serious outcomes and have an elevated tendency toward public exploit availability, reflecting the web-application attack surface and the access-control complexity of a commerce platform. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sunshinephotocart over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4301MEDIUM The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. | Jan 9, 2023 | 6.1 | 32 | NO | YES |
CVE-2024-30221CRITICAL Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1. | Mar 28, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-40692HIGH Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions. | Feb 2, 2023 | 8.8 | 28 | NO | NO |
CVE-2026-57703MEDIUM Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. | Jul 23, 2026 | 6.3 | 27 | NO | NO |
CVE-2025-68535CRITICAL Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue | Dec 24, 2025 | 9.1 | 27 | NO | NO |
CVE-2025-31084CRITICAL Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/ | Apr 1, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-43971MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects S | Sep 18, 2024 | 6.1 | 27 | NO | YES |
CVE-2024-30194MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects S | Mar 27, 2024 | 6.1 | 27 | NO | YES |
CVE-2025-62892CRITICAL Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects | Oct 27, 2025 | 9.1 | 26 | NO | NO |
CVE-2024-44038CRITICAL Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue | Nov 1, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sunshinephotocart.
Media articles that mention a CVE ID that affects a product developed by Sunshinephotocart — matched by CVE ID, not by vendor name.