Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/innocommerce/innoshop

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-18959 is a path traversal vulnerability in yushine InnoShop versions 0.8.0, 0.8.1, and 0.8.2. It affects the FileManagerController::destroyFiles function in the Files Endpoint component, allowing remote attackers to manipulate file paths. The vendor has not responded to the disclosure, and no official fix is currently available. Exploit code has been published, but no known widespread exploitation has been reported. The vulnerability has a medium severity rating with a CVSS score of 5.3.

Join the discussion
CVE-2026-39250: n/aCVE-2026-39250
0

An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfaces, leading to further dangerous operations.

Join the discussion

A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Installation Endpoint. The manipulation leads to improper authentication. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 45758e4ec22451ab944ae2ae826b1e70f6450dc9. It is recommended to apply a patch to fix this issue.

Join the discussion
CVE-2024-57277: n/aCVE-2024-57277
0

InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/innocommerce/innoshop
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses