CVE-2017-17951: PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.

Affected products

Published 2017-12-28. Last modified 2026-06-17.