Multiple Vulnerabilities Found in NivoCart Affecting Admin Access
Article Content
- •NivoCart versions up to 2.4.0 are vulnerable to two critical issues.
- •CVE-2026-94105 allows disabling of password recovery for unauthenticated users.
- •CVE-2026-94107 enables unauthorized admin access through predictable tokens.
NivoCart versions up to 2.4.0 are affected by two vulnerabilities, CVE-2026-94105 and CVE-2026-94107, both published on 2026-09-20. CVE-2026-94105 is a medium-severity vulnerability allowing unauthenticated attackers to disable password recovery by manipulating the admin password reset controller. CVE-2026-94107 presents a high-risk predictable password reset token vulnerability, enabling attackers to gain unauthorized administrative access by predicting recovery tokens. Both vulnerabilities impact internet-facing shops using NivoCart, particularly those with exposed recovery endpoints. The current status indicates that no active exploitation has been confirmed for CVE-2026-94105, while CVE-2026-94107 has not been confirmed as actively exploited either. Immediate remediation is recommended for both vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-33413 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…