Known vulnerabilities in express-cart
Vendor:
Mark Moffat
Software:
express-cart
Software CPE:
cpe:2.3:a:mrvautin:express-cart:*:*:*:*:*:*:*:*
Website:
https://github.com/mrvautin
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU31895 - Cross-Site Request Forgery (CSRF) |
CWE-352 | Low | 1.1.17 | 27.07.2020 |
SB2020072737 |
||
| #VU37067 - Unrestricted Upload of File with Dangerous Type CVE-2018-3758 |
CWE-434 | High | 1.1.7 | 07.06.2018 |
SB2018060728 |