See how ecshop compares to other vendors in security performance
SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component.
Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/articlecat.php.
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) proshow or (2) disppro action to the default URI.
SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the ordersn parameter in an orderquery action.