CVE-2023-26687: Cs-Cart Multivendor

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.

Affected products

  • Cs-Cart Cs-Cart Multivendor: version 4.16.1 only

Published 2024-09-25. Last modified 2026-06-17.