OsVault/npm/@evershop/evershop
npm1 critical

@evershop/evershop

10 known vulnerabilities · 1 critical · 1 high

CVE-2023-46498CRITICAL

Code execution in evershop

Published Dec 8, 2023
CVE-2025-67419

evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API

Published Jan 5, 2026
CVE-2023-46497MEDIUM

Directory Traversal in evershop

Published Dec 8, 2023
CVE-2023-46495MEDIUM

Cross-site Scripting in evershop

Published Dec 8, 2023
CVE-2025-12919

EverShop is vulnerable to Unauthorized Order Information Access (IDOR)

Published Nov 9, 2025
CVE-2025-67427

evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API

Published Jan 5, 2026
CVE-2023-46499MEDIUM

Cross-site Scripting in evershop

Published Dec 8, 2023
CVE-2023-46493MEDIUM

Directory Traversal in evershop

Published Dec 8, 2023
CVE-2023-46494MEDIUM

Cross Site Scripting in evershop

Published Dec 8, 2023
CVE-2023-46496HIGH

Directory Traversal in evershop

Published Dec 8, 2023
Check your entire dependency tree at onceRun dependency scan →