Known vulnerabilities in CoCart – Headless REST API for WooCommerce
Ship your headless WooCommerce storefront faster. CoCart is the REST API built for Next.js, React, Vue, and any modern frontend — developer-first.
3Reported vulnerabilities
7.5Highest CVSS score
4.9.2Latest version
1,000+Active installs
What to do now
Update CoCart – Headless REST API for WooCommerce to 4.9.0 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-10524 | High | 0.3% | 0 up to (but not including) 4.9.0 | 4.9.0 |
August 6, 2026 |
| CVE-2026-59536 | Medium | 0.2% | 4.8.4 and earlier | 4.9.0 |
July 23, 2026 |
| CVE-2023-47241 | Medium | 0.4% | 3.11.2 and earlier | 3.12.0 |
November 7, 2023 |