Skip to main content

Vendor/product archive

express-cart_project / express-cart CVEs

Beta · best-effort

4 CVEs tagged to express-cart_project / express-cart0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2020-22403

Published Aug 12, 2021

Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32573

Published May 11, 2021

The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely o…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1