CVE-2018-16483: Express-Cart Project Express-Cart

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.

Affected products

Published 2019-02-01. Last modified 2026-06-17.