Simple shopping cart
This hub aggregates every CVE we track for Simple shopping cart, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
0
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM8HIGH7
Monthly trend
0
0
0
0
0
1
0
0
0
2
3
0
3
0
0
0
0
3
0
0
0
1
0
1
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Simple shopping cart.
- CVE-2026-48868WordPress Simple Shopping Cart plugin <= 5.2.9 - Insecure Direct Object References (IDOR) vulnerability7.5
- CVE-2026-0552Simple Shopping Cart <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsc_display_product' Shortcode6.4
- CVE-2025-14248code-projects Simple Shopping Cart adminlogin.php sql injection7.3
- CVE-2025-14247code-projects Simple Shopping Cart additems.php sql injection6.3
- CVE-2025-14246code-projects Simple Shopping Cart settings.php sql injection6.3
- CVE-2025-7609code-projects Simple Shopping Cart register.php sql injection7.3
- CVE-2025-7608code-projects Simple Shopping Cart userlogin.php sql injection7.3
- CVE-2025-7607code-projects Simple Shopping Cart save_order.php sql injection7.3
- CVE-2025-3890WordPress Simple PayPal Shopping Cart <= 5.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode6.4
- CVE-2025-3874WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference6.5
- CVE-2025-3889WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference via 'quantity'5.3
- CVE-2025-3529WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Information Exposure via file_url Parameter8.2
- CVE-2025-3530WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Product Price Manipulation7.5
- CVE-2024-12622WordPress Simple Shopping Cart <= 5.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2023-6497WordPress Simple Shopping Cart <= 4.7.1 - Authenticated(Administrator+) Stored Cross-Site Scripting4.4
Product normalization is registry-driven with AI assist and human review. How it works