Info Welcart Welcart E-Commerce vulnerabilities
5 known vulnerabilities affecting info_welcart/welcart_e-commerce.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1UNKNOWN3
Vulnerabilities
Page 1 of 1
CVE-2025-62953HIGHCVSS 8.8≤ 2.11.242025-10-27
CVE-2025-62953 [HIGH] CWE-862 CVE-2025-62953: Missing Authorization vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Exploiting
Missing Authorization vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcart e-Commerce: from n/a through <= 2.11.24.
cvelistv5nvd
CVE-2025-58984UNKNOWN≤ 2.11.202025-09-09
CVE-2025-58984 CWE-79 CVE-2025-58984: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.20.
cvelistv5nvd
CVE-2025-54012UNKNOWN≤ 2.11.162025-08-20
CVE-2025-54012 CWE-502 CVE-2025-54012: Deserialization of Untrusted Data vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows
Deserialization of Untrusted Data vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Object Injection.This issue affects Welcart e-Commerce: from n/a through <= 2.11.16.
cvelistv5nvd
CVE-2025-54013UNKNOWN≤ 2.11.162025-07-16
CVE-2025-54013 CWE-79 CVE-2025-54013: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.16.
cvelistv5nvd
CVE-2025-47511MEDIUMCVSS 6.5≤ 2.11.132025-06-09
CVE-2025-47511 [MEDIUM] CWE-22 CVE-2025-47511: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Path Traversal.This issue affects Welcart e-Commerce: from n/a through <= 2.11.13.
cvelistv5nvd