Known Vulnerabilities for products from Express-cart Project
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Express-cart Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-32573 json | ** DISPUTED ** The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field... | 4.8 - MEDIUM | 2021-05-11 | 2023-11-07 |
| CVE-2020-22403 json | The express-cart package through 1.1.10 for Node.js allows CSRF. | 8.8 - HIGH | 2021-08-12 | 2023-07-06 |
| CVE-2018-16483 json | A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the applicati... | 8.8 - HIGH | 2019-02-01 | 2020-08-24 |
| CVE-2018-3758 json | Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting mac... | 8.8 - HIGH | 2018-06-07 | 2023-01-30 |
Known software with vulnerabilities from Express-cart Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Express-cart Project | Express-cart | 0.0.1 |