See how ecshop compares to other vendors in security performance
Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/articlecat.php.
SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component.
SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the ordersn parameter in an orderquery action.
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) proshow or (2) disppro action to the default URI.