Export limit exceeded: 385330 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 385330 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-63607 | 1 Nooncarlett | 1 Techstore | 2026-09-01 | N/A |
| TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser. | ||||
| CVE-2025-66845 | 2 Nooncarlett, Techstore | 2 Techstore, Techstore | 2026-01-05 | 6.1 Medium |
| A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoint reflects the id query parameter directly into the HTML response without output encoding or sanitization, allowing execution of arbitrary JavaScript code in a victim’s browser. | ||||
| CVE-2025-63543 | 2 Nooncarlett, Techstore | 2 Techstore, Techstore | 2025-11-21 | 6.1 Medium |
| TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter. | ||||
| CVE-2025-63544 | 2 Nooncarlett, Techstore | 2 Techstore, Techstore | 2025-11-21 | 6.1 Medium |
| TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter. | ||||
Page 1 of 1.