CVE-2025-67427: Evershop
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET /images" API. The vulnerability occurs due to insufficient validation of the "src" query parameter, which permits arbitrary HTTP or HTTPS URIs, resulting in unexpected requests against internal and external networks.
Affected products
- Evershop Evershop: up to and including 2.1.0
Published 2026-01-05. Last modified 2026-06-17.