A SQL injection vulnerability, identified as CVE-2024-24112, in the exrick xmall e-commerce platform is reportedly being actively exploited. The vulnerability was first disclosed on February 6, 2024, but evidence of exploitation emerged significantly later, with the first recorded instance on September 14, 2026—approximately 951 days after its initial publication.
The vulnerability's lifecycle began with its reservation on January 25, 2024, followed by its public disclosure on February 6, 2024. Despite the long period between disclosure and confirmed exploitation, the vulnerability has not been added to the U.S. federal CISA Known Exploited Vulnerabilities (KEV) catalog or the European Union Agency for Cybersecurity (ENISA) KEV list.
The claim of active exploitation is primarily supported by a listing in the commercial research catalog VulnCheck KEV, which first reported it on September 14, 2026. This information is mirrored by the CIRCL aggregator, though CIRCL is not counted as an independent corroborating source. Public exploitation evidence was also reported on September 14, 2026, via dashboard.shadowserver.org/statistics/honeypot/vulnerability, which aggregates data from sources like VulnCheck and CIRCL.
The vulnerability currently has no assigned CVSS severity score, and its Exploit Prediction Scoring System (EPSS) score is 3.3%, placing it in the 88.2nd percentile. This indicates a relatively low probability of exploitation compared to other vulnerabilities, despite the confirmed active attacks.
The exrick xmall platform is an open-source e-commerce system. The specific details of the SQL injection flaw and the methods of exploitation have not been widely detailed in public reports, beyond its identification as CVE-2024-24112. Users of the exrick xmall platform are advised to consult official vendor advisories for patching information, though no patch window has been publicly specified in the available reports.






