ShopXO Template Handler Injection Vulnerability Leading to Remote Code Execution

Vulnerability

A remote code execution vulnerability has been identified in ShopXO versions through 6.4.0. This issue arises in the file app/service/ThemeAdminService.php, within the Template Handler component. The vulnerability allows for injection, enabling remote exploitation.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where ShopXO is hosted.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
6.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.