VYPR

ecommerce-website

by Winston Dsouza

CVEs (2)

  • CVE-2022-45990MedDec 5, 2022
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.

  • CVE-2025-13793MedNov 30, 2025
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the…