CVE-2026-28213 – EverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset Token in API Response

CVE ID : CVE-2026-28213

Published : Feb. 26, 2026, 10:31 p.m. | 39 minutes ago

Description : EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the “Forgot Password” functionality. When specifying a target email address, the API response returns the password reset token. This allows an attacker to take over the associated account. Version 2.1.1 fixes the issue.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه