Vulnerabilities > Vanguard Project > Marketplace Digital Products PHP > 1.9

DATE CVE VULNERABILITY TITLE RISK
2017-12-28 CVE-2017-17937 Cross-site Scripting vulnerability in Vanguard Project Marketplace Digital products PHP
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
network
low complexity
vanguard-project CWE-79
6.1
2017-12-28 CVE-2017-17936 Cross-Site Request Forgery (CSRF) vulnerability in Vanguard Project Marketplace Digital products PHP
Vanguard Marketplace Digital Products PHP has CSRF via /search.
network
low complexity
vanguard-project CWE-352
8.8