CVE-2024-46307: Sparkshop

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

Affected products

  • Sparkshop Sparkshop: up to and including 1.1.6

Published 2024-10-09. Last modified 2026-07-05.