logo

CVE-2026-25993: Critical EverShop SQL Injection (CVSS 9.3) Exposes Stores

ID: 193e7332-a9f5-5cfa-a887-344c746494e7

STIX ID: report--193e7332-a9f5-5cfa-a887-344c746494e7

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical Second-Order SQL Injection (CVE-2026-25993) was found in EverShop’s url_key handling for product categories; malicious strings can be stored and later executed during category event processing, enabling database manipulation, data theft, or potential administrative takeover. The flaw carries a CVSSv4 score of 9.3 and maintainers released a patch—upgrade to EverShop 2.1.1 or later is strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.