CVE-2018-3758: Express-Cart Project Express-Cart

High severity, CVSS 8.8. EPSS: 27.5% chance of exploitation in the next 30 days.

Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.

Affected products

Published 2018-06-07. Last modified 2026-06-17.