CVE-2025-27130

Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product.


We have discovered 1,968 live websites that are affected by CVE-2025-27130.

Run a Free Instant Scan




Affected Software

Product  Welcart
Category Ecommerce
Vulnerable Domains1,968 live websites (100% of Welcart install base)
Vulnerable Versions
  • from 0 through 2.11.6
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)



Details

  • Published - Apr 1, 2025
  • Updated - Apr 1, 2025

Website Distribution by Country

Number of websites using CVE-2025-27130
United States39 websites



Japan1,807 websites
Australia2 websites
Netherlands2 websites
Bulgaria1 websites
Brazil1 websites
China1 websites
Germany1 websites
Spain1 websites

Website Distribution by TLD

Number of websites using CVE-2025-27130
.com981 websites
.jp419 websites
.co.jp244 websites
.net149 websites
.org27 websites
.info25 websites
.co4 websites
.be1 websites

Websites affected by CVE-2025-27130

Top websites that are affected by CVE-2025-27130. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com Japan***,***
***.**.jp Japan***,***
********.jp Japan***,***
****.org Japan***,***
******.net Japan***,***
*************.com Japan***,***
*********.com Japan*,***,***
********.jp Japan*,***,***
*******.com Japan*,***,***
*****.org Japan*,***,***
See full domain list

FAQ

A total of 1,968 websites have been identified as vulnerable to CVE-2025-27130, based on global website indexing conducted by WebTechSurvey.
The Welcart is affected by the CVE-2025-27130 vulnerability.
Welcart versions up to 2.11.6 are vulnerable to CVE-2025-27130.
CVE-2025-27130 is resolved in version 2.11.6 of Welcart.