Tp Shop is an e-commerce platform with a narrow, focused product footprint that operates in a high-exposure category where web applications frequently encounter authentication and data-handling risks. The recorded vulnerabilities center on the platform itself and reflect typical application-layer exposure patterns. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tp Shop over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9919CRITICAL A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtain sensitive information, attack intranet hosts, or poss | May 2, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-18164CRITICAL SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter. | Aug 17, 2021 | 9.8 | 29 | NO | NO |
CVE-2017-16614CRITICAL SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command exec | Mar 30, 2018 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tp Shop.
Media articles that mention a CVE ID that affects a product developed by Tp Shop — matched by CVE ID, not by vendor name.