VendorsInspireUImstore_apiany version
Vulnerabilities

InspireUI MStore API any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2021-24148
MStore API < 3.2.0 - Authentication Bypass With Sign In With Apple
Published 2021-03-18 · Modified
10.0EPSS 0.034
CVE-2023-2732
MStore API <= 3.9.2 - Authentication Bypass
Published 2023-05-25 · Modified
9.8EPSS 0.675
CVE-2023-3077
MStore API < 3.9.8 - Unauthenticated Blind SQLi
Published 2023-07-10 · Modified
9.8EPSS 0.055
CVE-2023-3197
MStore API <= 4.0.1 - Unauthenticated SQL Injection
Published 2023-06-24 · Modified
9.8EPSS 0.039
CVE-2023-2734
MStore API <= 3.9.1 - Authentication Bypass
Published 2023-05-25 · Modified
9.8EPSS 0.038
CVE-2023-3277
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
Published 2023-11-03 · Modified
9.8EPSS 0.029
CVE-2023-3076
MStore API < 3.9.9 - Unauthenticated Privilege Escalation
Published 2023-07-10 · Modified
9.8EPSS 0.022
CVE-2020-36713
MStore API <= 2.1.5 - Authentication Bypass
Published 2023-06-07 · Modified
9.8EPSS 0.016
CVE-2023-2733
MStore API <= 3.9.0 - Authentication Bypass
Published 2023-05-25 · Modified
9.8EPSS 0.012
CVE-2024-6328
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass
Published 2024-07-12 · Modified
9.8EPSS 0.007
CVE-2023-45055
WordPress MStore API Plugin <= 4.0.6 is vulnerable to SQL Injection
Published 2023-11-06 · Modified
9.8EPSS 0.006
CVE-2024-8242
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload
Published 2024-09-13 · Analyzed
8.8EPSS 0.008
CVE-2023-50878
WordPress MStore API Plugin <= 4.10.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-12-29 · Modified
8.8EPSS 0.002
CVE-2024-7628
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover
Published 2024-08-15 · Analyzed
8.1EPSS 0.007
CVE-2022-47614
WordPress MStore API Plugin <= 3.9.7 is vulnerable to SQL Injection
Published 2023-06-23 · Modified
7.5EPSS 0.006
CVE-2024-8269
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration
Published 2024-09-13 · Analyzed
7.3EPSS 0.004
CVE-2025-3438
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation
Published 2025-05-02 · Analyzed
7.3EPSS 0.003
CVE-2024-11179
MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection
Published 2024-11-20 · Analyzed
6.5EPSS 0.005
CVE-2024-12042
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)
Published 2024-12-13 · Analyzed
5.4EPSS 0.003
CVE-2023-3131
MStore API < 3.9.7 - Subscriber+ Unauthorized Settings Update
Published 2023-07-10 · Modified
4.3EPSS 0.006
CVE-2023-3200
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message Update
Published 2023-06-14 · Modified
4.3EPSS 0.003
CVE-2023-3201
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update
Published 2023-06-14 · Modified
4.3EPSS 0.003
CVE-2023-3203
MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit Update
Published 2023-06-14 · Modified
4.3EPSS 0.003
CVE-2023-3198
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status Update
Published 2023-06-14 · Modified
4.3EPSS 0.003
CVE-2023-3202
MStore API <= 3.9.6 - Cross-Site Request Forgery to Firebase Server Key Update
Published 2023-07-12 · Modified
4.3EPSS 0.003
CVE-2023-3199
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update
Published 2023-07-12 · Modified
4.3EPSS 0.003
CVE-2025-4683
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation
Published 2025-05-27 · Analyzed
4.3EPSS 0.003
CVE-2023-3209
MStore API < 3.9.7 - Settings Update via CSRF
Published 2023-07-10 · Modified
3.5EPSS 0.003