CVE-2025-67427: Evershop

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET /images" API. The vulnerability occurs due to insufficient validation of the "src" query parameter, which permits arbitrary HTTP or HTTPS URIs, resulting in unexpected requests against internal and external networks.

Affected products

  • Evershop Evershop: up to and including 2.1.0

Published 2026-01-05. Last modified 2026-06-17.