EverShop contains a second-order SQL injection in its category update and deletion event handling logic. The application constructs SQL statements by string-concatenating path/request_path values derived from the category url_key stored in the database, and then executes the resulting SQL via execute(). If an attacker is able to persist a malicious payload into url_key, that payload is later incorporated into dynamically built SQL during subsequent event processing, modifying the query and resulting in SQL injection. The issue is patched starting in EverShop v2.1.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Dockerized exploitation lab for CVE-2026-25993, a second-order SQL injection affecting EverShop v2.1.0. It is not an automated exploit script; instead, it provisions a vulnerable target environment and documents how an operator can exploit the flaw through the application's category management workflow. Repository structure: Dockerfile builds a Node 18-based container, clones EverShop v2.1.0 from GitHub, installs dependencies, compiles the app and database artifacts, and sets /entrypoint.sh as the container entrypoint. docker-compose.yml defines two services: a PostgreSQL 16 backend and the EverShop application, exposing the web app on port 3000 and wiring database credentials and JWT secrets through environment variables. entrypoint.sh waits for PostgreSQL readiness, writes /evershop/.env, creates required directories, builds frontend assets, starts EverShop, creates an admin user via the bundled CLI, and runs seed.js. seed.js connects directly to PostgreSQL using EverShop's internal connection module and seeds categories, products, a collection, and a homepage widget to make the lab usable. Exploit purpose and capability: The README describes the vulnerable behavior: the category url_key field only rejects whitespace, allowing SQL metacharacters such as single quotes and concatenation operators. A later category update triggers an event subscriber that constructs raw SQL using string concatenation, causing stored malicious input to execute in a second-order manner. The intended outcome is database dumping via the application's own SQL execution path. The documented exploitation goals are to retrieve the PostgreSQL version, enumerate tables, and extract data from sensitive tables such as admin_user, customer, and product. Attack surface: The practical attack vector is web-based/admin-driven interaction with the EverShop interface at localhost:3000, especially category creation and update functionality. The exploit depends on asynchronous backend processing of category URL rewrites, with results appearing in child url_rewrite entries after a delay. This makes it a realistic lab for manual exploitation and validation of the SQL injection rather than a scanner or detection-only artifact. Notable endpoints and artifacts include the local storefront (http://localhost:3000), admin API (/api/v1), admin panel (/admin), internal PostgreSQL host evershop-db:5432, persistent database storage at /var/lib/postgresql/data, and generated application files such as /evershop/.env. Default credentials are hardcoded for lab access: admin@evershop.io / password123.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.