Browse all 4 CVE security advisories affecting ecwid. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Ecwid provides e-commerce solutions enabling businesses to create online stores across multiple platforms. Historically, vulnerabilities have included stored cross-site scripting (XSS) allowing attacker-controlled content injection, remote code execution (RCE) in specific plugin implementations, and privilege escalation flaws in administrative interfaces. Security assessments have identified input validation weaknesses as a recurring issue. While no major public security incidents have been widely reported, the platform's CVE history reflects typical web application vulnerabilities common in e-commerce systems. The company has addressed reported issues through security patches and updates, maintaining a moderate security posture relative to industry standards.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-1750 | Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access — Ecwid by Lightspeed Ecommerce Shopping CartCWE-269 | 8.8 | High | 2026-02-15 |
| CVE-2024-13795 | Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message — Ecwid by Lightspeed Ecommerce Shopping CartCWE-352 | 4.3 | Medium | 2025-02-18 |
| CVE-2024-2456 | Ecwid Ecommerce Shopping Cart <= 6.12.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode — Ecwid by Lightspeed Ecommerce Shopping CartCWE-79 | 6.4 | Medium | 2024-04-09 |
| CVE-2022-2432 | Ecwid Ecommerce Shopping Cart <= 6.10.23 - Cross-Site Request Forgery to Settings/Options Update — Ecwid Ecommerce Shopping CartCWE-352 | 8.8 | High | 2022-09-06 |
This page lists every published CVE security advisory associated with ecwid. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.