Medium severity6.1NVD Advisory· Published Sep 12, 2025· Updated Jun 17, 2026
CVE-2025-52074
CVE-2025-52074
Description
PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:phpgurukul:online_shopping_portal:2.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:phpgurukul:online_shopping_portal:2.1:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: = 2.1
Patches
Vulnerability mechanics
References
1- github.com/NullMinds/CVE-Hunting/blob/main/Online%20Shopping%20Portal/Stored%20XSS%20in%20Quantity%20Parameter.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.