sparkshop CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

sparkshop vulnerability overview

Aggregates CVE and security vulnerability intelligence across all sparkshop-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk ssrf and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-50722 Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component [email protected] 9.8 0.72% 2025-08-25 2026-06-17
CVE-2024-57685 An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file. [email protected] 5.3 0.40% 2025-02-24 2026-06-17
CVE-2024-48107 SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server. [email protected] 6.5 0.17% 2024-10-28 2026-06-17
CVE-2024-46307 A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products. [email protected] 7.5 0.46% 2024-10-09 2026-07-04
CVE-2024-40425 File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component. [email protected] 9.8 0.71% 2024-07-16 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence