SQL Injection Vulnerability in Mult-E-Cart Ultimate by Multecart
CVE-2021-47909
Key Information:
- Vendor
Techraft
- Vendor
- CVE Published:
- 1 February 2026
Badges
What is CVE-2021-47909?
Mult-E-Cart Ultimate version 2.4 is susceptible to multiple SQL injection vulnerabilities across its inventory, customer, vendor, and order modules. This flaw allows remote attackers who possess privileged vendor or administrative roles to manipulate the 'id' parameter, enabling them to execute arbitrary SQL commands. Such an exploit can lead to unauthorized access and compromise the integrity of the database management system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Digital Multivendor Marketplace Online Store 2.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
