Vulnerabilities > Broadleafcommerce
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-21 | CVE-2023-33725 | Cross-site Scripting vulnerability in Broadleafcommerce Broadleaf Commerce Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. | 6.1 |
2020-10-29 | CVE-2020-21266 | Cross-site Scripting vulnerability in Broadleafcommerce Broadleaf Commerce 5.1.14Ga Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability. | 6.1 |