⤷ Title: CVE-2026-25993: Critical EverShop SQL Injection (CVSS 9.3) Exposes Stores
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:23:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_25993 #Database Takeover #e_commerce security #EverShop #graphql #Patch Alert #React Commerce #Second_Order Injection #sql injection #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:23:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_25993 #Database Takeover #e_commerce security #EverShop #graphql #Patch Alert #React Commerce #Second_Order Injection #sql injection #Web Security
Daily CyberSecurity
CVE-2026-25993: Critical EverShop SQL Injection (CVSS 9.3) Exposes Stores
Critical EverShop flaw CVE-2026-25993 (CVSS 9.3) allows Second-Order SQL Injection via URL keys. Update to v2.1.1 to prevent store takeover.