npm1 critical
@evershop/evershop
10 known vulnerabilities · 1 critical · 1 high
evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API
Published Jan 5, 2026
evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API
Published Jan 5, 2026
EverShop is vulnerable to Unauthorized Order Information Access (IDOR)
Published Nov 9, 2025
Check your entire dependency tree at onceRun dependency scan →