Known vulnerabilities in the Mstore Api plugin
32 security advisories have been published for the Mstore Api plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- MStore API - Broken Access Control (CVE-2026-18234) MEDIUM
- MStore API - Broken Access Control (CVE-2026-18233) MEDIUM
- MStore API - Privilege Escalation (CVE-2026-27543) HIGH
- Mstore Api - Security Vulnerability (CVE-2026-16041) HIGH
- Mstore Api - Security Vulnerability (CVE-2026-16039) MEDIUM
- Mstore Api - Security Vulnerability (CVE-2026-16038) CRITICAL
- Mstore Api - Security Vulnerability (CVE-2026-16030) HIGH
- Mstore Api - Cross-Site Scripting (XSS) (CVE-2026-3568) MEDIUM
- Mstore Api - Broken Access Control (CVE-2025-4683) MEDIUM
- Mstore Api - Privilege Escalation (CVE-2025-3438) MEDIUM
- Mstore Api - Cross-Site Scripting (XSS) (CVE-2024-12042) MEDIUM
- Mstore Api - SQL Injection (CVE-2024-11179) MEDIUM
- Mstore Api - Security Vulnerability (CVE-2024-8269) HIGH
- Mstore Api - Remote Code Execution (CVE-2024-8242) MEDIUM
- Mstore Api - Authentication Bypass (CVE-2024-7628) HIGH
- Mstore Api - Authentication Bypass (CVE-2024-6328) CRITICAL
- Mstore Api - Privilege Escalation (CVE-2023-3277) CRITICAL
- Mstore Api - Cross-Site Request Forgery (CSRF) (CVE-2023-3202) MEDIUM
- Mstore Api - Cross-Site Request Forgery (CSRF) (CVE-2023-3199) MEDIUM
- Mstore Api - Security Vulnerability (CVE-2023-3131) MEDIUM
- Mstore Api - Security Vulnerability (CVE-2023-3209) LOW
- Mstore Api - SQL Injection (CVE-2023-3077) CRITICAL
- Mstore Api - Security Vulnerability (CVE-2023-3076) CRITICAL
- Mstore Api - SQL Injection (CVE-2023-3197) CRITICAL
- Mstore Api - Cross-Site Request Forgery (CSRF) (CVE-2023-3203) MEDIUM
- Mstore Api - Cross-Site Request Forgery (CSRF) (CVE-2023-3201) MEDIUM
- Mstore Api - Cross-Site Request Forgery (CSRF) (CVE-2023-3200) MEDIUM
- Mstore Api - Cross-Site Request Forgery (CSRF) (CVE-2023-3198) MEDIUM
- Mstore Api - Authentication Bypass (CVE-2023-2734) CRITICAL
- Mstore Api - Authentication Bypass (CVE-2023-2733) CRITICAL