Vulnerabilities > Shopkit Project

DATE CVE VULNERABILITY TITLE RISK
2021-09-24 CVE-2020-20508 Cross-site Scripting vulnerability in Shopkit Project Shopkit 2.7
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.
network
low complexity
shopkit-project CWE-79
6.1