CVE-2025-27130: Welcart E-Commerce

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product.

Affected products

  • Welcart Welcart E-Commerce: up to and including 2.11.6

Published 2025-04-01. Last modified 2026-06-17.