CVE-2018-3758: Express-Cart Project Express-Cart
High severity, CVSS 8.8. EPSS: 27.5% chance of exploitation in the next 30 days.
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
Affected products
- Express-Cart Project Express-Cart: before 1.1.7 (fixed in 1.1.7)
Published 2018-06-07. Last modified 2026-06-17.