Known Vulnerabilities for products from Tp-shop
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Tp-shop".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-58379 json | Not Provided | 2026-07-03 | 2026-07-13 | |
| CVE-2026-57405 json | Not Provided | 2026-07-13 | 2026-07-13 | |
| CVE-2026-54390 json | Not Provided | 2026-06-18 | 2026-06-23 | |
| CVE-2026-48518 json | Not Provided | 2026-06-15 | 2026-06-16 | |
| CVE-2026-40748 json | Not Provided | 2026-06-17 | 2026-06-17 | |
| CVE-2026-39499 json | Not Provided | 2026-06-15 | 2026-06-15 | |
| CVE-2026-39498 json | Not Provided | 2026-06-15 | 2026-06-15 | |
| CVE-2026-39472 json | Not Provided | 2026-06-15 | 2026-06-15 | |
| CVE-2026-39470 json | Not Provided | 2026-06-15 | 2026-06-15 | |
| CVE-2026-39434 json | Not Provided | 2026-06-15 | 2026-06-15 | |
| CVE-2020-18164 json | SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter. | 9.8 - CRITICAL | 2021-08-17 | 2021-08-25 |
| CVE-2018-9919 json | A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtai... | 9.8 - CRITICAL | 2018-05-02 | 2018-06-13 |
| CVE-2017-16614 json | SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack ... | 9.8 - CRITICAL | 2018-03-30 | 2018-04-23 |