Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ictrun/Evershop

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-72843 is a critical missing authorization vulnerability in EverShop versions before 2.2.1. The customer update API route is publicly accessible without authentication, allowing unauthenticated attackers to modify any customer's email and password by knowing their UUID. This enables account takeover and locking out legitimate users. The vulnerability is fixed in version 2.2.1 by changing the route access to private.

Join the discussion

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns the password reset token. This allows an attacker to take over the associated account. Version 2.1.1 fixes the issue.

Join the discussion
CVE-2025-67419: n/aCVE-2025-67419
0

A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles during the processing of SVG files, resulting in unbounded resource consumption and system-wide denial of service.

Join the discussion
CVE-2025-67427: n/aCVE-2025-67427
0

CVE-2025-67427 is a Blind Server-Side Request Forgery (SSRF) vulnerability affecting evershop version 2.1.0 and earlier. It allows unauthenticated attackers to exploit the "GET /images" API endpoint by manipulating the "src" query parameter to force the server to initiate arbitrary HTTP or HTTPS requests. This occurs due to insufficient validation of the input, enabling attackers to make requests to internal or external network resources without authentication or user interaction. The vulnerability has a CVSS score of 6.5, indicating medium severity, primarily impacting confidentiality and integrity but not availability. No known exploits are currently in the wild, and no official patches have been released yet. European organizations using evershop 2.1.

Join the discussion
CVE-2025-65844: n/aCVE-2025-65844
0

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentication by default, and server-side validation of uploaded files is insufficient. This can be abused to upload arbitrary content (including non-image files) which could impersonate user/admin login panels (exfiltrating credentials) and to perform a denial-of-service attack by exhausting disk space.

Join the discussion

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/ictrun/Evershop
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses