CVE-2018-11372: Iscripts Eswap

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.

Affected products

Published 2018-05-22. Last modified 2026-06-17.