CVE-2020-18164: TP-Shop

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.

Affected products

  • TP-Shop TP-Shop: from 2.0.5, up to and including 3.0.0

Published 2021-08-17. Last modified 2026-06-17.