VulnSea

nivocart vulnerabilities

CVEs whose affected-version data names the nivocart package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-94104High· 8.8
yesterday

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-o…

Twilightnivocart · nivocartEPSS 0.67%via NVD
CVE-2026-94105Medium· 5.3
yesterday

NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter

NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter. Attackers c…

Sunlitnivocart · nivocartEPSS 0.25%via NVD
CVE-2026-94107High· 8.1
yesterday

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10)

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can req…

Twilightnivocart · nivocartEPSS 0.42%via NVD
nivocart vulnerabilities (CVEs) · VulnSea