Vulnerabilities (CVE)

Filtered by vendor Ec-cube Subscribe
Filtered by product Business Form Output
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20742 1 Ec-cube 2 Business Form Output, Ec-cube 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.
CVE-2021-20744 1 Ec-cube 2 Business Form Output, Ec-cube 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.