Vulnerabilities > Merchandise Online Store Project > Merchandise Online Store > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-10-11 CVE-2022-42236 Cross-site Scripting vulnerability in Merchandise Online Store Project Merchandise Online Store 1.0
A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form.
network
low complexity
merchandise-online-store-project CWE-79
5.4
2022-05-13 CVE-2022-30381 Unspecified vulnerability in Merchandise Online Store Project Merchandise Online Store 1.0
Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.
network
low complexity
merchandise-online-store-project
6.5