CVE-2026-7630

Published
View on NVD ↗
CVSS v3
7.3
HIGH
CVSS v2
7.5
HIGH
Affected
1
PROJECT

Description

A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Installation Endpoint. The manipulation leads to improper authentication. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 45758e4ec22451ab944ae2ae826b1e70f6450dc9. It is recommended to apply a patch to fix this issue.

InnoShop is an AI-powered open source e-commerce system built on Laravel 12, designed for global commerce. It supports multiple AI models for intelligent automation, with native multi-language and multi-currency capabilities. The modular architecture and flexible plugin/theme system make it highly adaptable to diverse business needs.
GitHubGitHub
627