CVE-2016-4862: Cs-Cart

High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.

Affected products

  • Cs-Cart Cs-Cart: up to and including 4.3.9

Published 2017-04-20. Last modified 2026-06-17.