CVE-2026-28213

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/02/2026
Last modified:
28/02/2026

Description

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns the password reset token. This allows an attacker to take over the associated account. Version 2.1.1 fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:evershop:evershop:*:*:*:*:*:node.js:*:* 2.1.1 (excluding)