Medium severityNVD Advisory· Published Dec 4, 2025· Updated Apr 15, 2026
CVE-2025-66572
CVE-2025-66572
Description
Loaded Commerce 6.6 contains a client-side template injection vulnerability that allows unauthenticated attackers to execute code on the server via the search parameter.
Affected products
1- Range: =6.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.