HarborGuard / CVE
Back to search
CRITICALCVE-2026-28213Published Modified CNA GitHub_M

CVE-2026-28213: EverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset Token in API Response

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns the password reset token. This allows an attacker to take over the associated account. Version 2.1.1 fixes the issue.

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • evershopcommerce / evershop
    < 2.1.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-28213: EverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset Token in API Response | HarborGuard CVE