Caddy – WooCommerce Side Cart & Free Shipping Bar

33 known CVEs 3K+ active installs

Scan My Site Free

UNKNOWN: 33
Known Vulnerabilities 33
CVE-2026-30852 UNKNOWN EPSS 0.3%
Published 2026-03-07 · Affected: *
Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 double-expands user-controlled input through the Ca
CVE-2026-30851 UNKNOWN EPSS 0.2%
Published 2026-03-07 · Affected: *
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injec
CVE-2026-27590 UNKNOWN EPSS 0.4%
Published 2026-02-24 · Affected: *
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and the
CVE-2026-27589 UNKNOWN EPSS 0.1%
Published 2026-02-24 · Affected: *
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint tha
CVE-2026-27588 UNKNOWN EPSS 0.3%
Published 2026-02-24 · Affected: *
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host l
CVE-2026-27587 UNKNOWN EPSS 0.3%
Published 2026-02-24 · Affected: *
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains pe
CVE-2026-27586 UNKNOWN EPSS 0.2%
Published 2026-02-24 · Affected: *
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to sil
CVE-2026-27585 UNKNOWN EPSS 0.2%
Published 2026-02-24 · Affected: *
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path re
CVE-2023-44487 UNKNOWN EPSS 1.0%
Published 2023-10-10 · Affected: *
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-44487 UNKNOWN EPSS 1.0%
Published 2023-10-10 · Affected: *
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-44487 UNKNOWN EPSS 1.0%
Published 2023-10-10 · Affected: *
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.0.2
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.0.9
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.0.12
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.0.14
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.1.0
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.2.1
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.3.0
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.3.1
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.3.3
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <7.0.0
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <7.1.0
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <7.2.7
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <2.1.4
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <2.1.5
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <2.1.6
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <3.0.0
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <4.0.0
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <4.0.1
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <4.0.2
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <4.0.3
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <4.0.12
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy
CVE-2017-5963 UNKNOWN EPSS 0.6%
Published 2017-02-12 · Affected: <6.0.1
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy

Is Caddy – WooCommerce Side Cart &amp; Free Shipping Bar running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free