Surecart is a payment-processing and checkout platform whose vulnerability profile centers on a single core product with a recurring pattern of cross-site scripting weaknesses in web-facing components. The exposure reflects common input-handling risks in e-commerce and form-processing applications where user data flows through page-generation logic without sufficient neutralization. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Surecart over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57314HIGH Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. | Jun 26, 2026 | 7.1 | 32 | NO | NO |
CVE-2026-57313MEDIUM Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. | Jun 26, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-39488MEDIUM Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a thro | Apr 8, 2026 | 6.5 | 22 | NO | NO |
CVE-2024-43970MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a thr | Sep 18, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-41241MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Stores plugin <= 2.5.0 versions. | Sep 27, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Surecart.
Media articles that mention a CVE ID that affects a product developed by Surecart — matched by CVE ID, not by vendor name.