Unrated severityNVD Advisory· Published Dec 23, 2025· Updated Dec 23, 2025
CVE-2025-66845
CVE-2025-66845
Description
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoint reflects the id query parameter directly into the HTML response without output encoding or sanitization, allowing execution of arbitrary JavaScript code in a victim’s browser.
Affected products
2- TechStore/TechStoredescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.