CVE-2018-11470: Iscripts Eswap

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.

Affected products

Published 2018-05-25. Last modified 2026-06-17.