Unrated severityNVD Advisory· Published Dec 31, 2006· Updated Apr 23, 2026
CVE-2006-6868
CVE-2006-6868
Description
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
6cpe:2.3:a:zen_cart:web_shopping_cart:1.1.2d:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:zen_cart:web_shopping_cart:1.1.2d:*:*:*:*:*:*:*
- cpe:2.3:a:zen_cart:web_shopping_cart:1.2.6d:*:*:*:*:*:*:*
- cpe:2.3:a:zen_cart:web_shopping_cart:1.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:zen_cart:web_shopping_cart:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:zen_cart:web_shopping_cart:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:zen_cart:web_shopping_cart:1.3.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.