CVE-2017-17957: PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.

Affected products

Published 2017-12-28. Last modified 2026-06-17.