CVE-2024-31025: Shopex Ecshop

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component.

Affected products

  • Shopex Ecshop: from 4.0, before 5 (fixed in 5)

Published 2024-04-04. Last modified 2026-06-17.