CVE-2023-45854: Shopkit Project Shopkit

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function.

Affected products

Published 2024-09-16. Last modified 2026-06-17.