CVE-2020-22403: Express-Cart Project Express-Cart

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.

Affected products

Published 2021-08-12. Last modified 2026-06-17.