CVE-2025-31048: Themify Shopo

Critical severity, CVSS 9.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through 1.1.4.

Affected products

  • Themify Shopo: up to and including 1.1.4

Published 2026-01-05. Last modified 2026-10-07.