npm1 critical
@evershop/evershop
10 known vulnerabilities · 1 critical · 1 high
evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API
Published Jan 5, 2026
EverShop is vulnerable to Unauthorized Order Information Access (IDOR)
Published Nov 9, 2025
evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API
Published Jan 5, 2026
Check your entire dependency tree at onceRun dependency scan →