๐Ÿ” CVE Alert

CVE-2021-47763

HIGH 8.2

Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries. Attackers can manipulate the sort parameter to reveal table and column names by sending crafted GET requests to the jsonapi/review endpoint.

CWE CWE-89
Vendor aimeos
Product aimeos laravel ecommerce platform
Published Jan 15, 2026
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for aimeos aimeos laravel ecommerce platform

Be the first to know when new high vulnerabilities affecting aimeos aimeos laravel ecommerce platform are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

Aimeos / Aimeos Laravel ecommerce platform
Aimeos 2021.10 LTS

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/50538 aimeos.org: https://aimeos.org aimeos.org: https://aimeos.org/laravel-ecommerce-package

Credits

Ilker Burak ADIYAMAN