V
Vexday
by TrueHacking
›
Briefing
Live
PT
ES
EN
Home
/
Technologies
/
evershopcommerce
Vulnerabilities in
evershopcommerce
2 results
CVE-2026-28213
CRITICAL
EverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset Token in API Response
EPSS
0.4%
CVE-2026-25993
CRITICAL
EverShop has a Second-Order SQL Injection in URL Rewrite Processing Derived from Category URL Keys
EPSS
0.3%