CVE-2016-1154: Cuore Ec-Cube Help Plugin
Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.
SQL injection vulnerability in the Help plug-in 1.3.5 and earlier in Cuore EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected products
- Cuore Ec-Cube Help Plugin: up to and including 1.3.5
Published 2016-02-19. Last modified 2026-06-17.