| Summary | Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions. |
|---|---|
| Publication Date | May 1, 2026, 3:16 a.m. |
| Registration Date | May 1, 2026, 4:07 a.m. |
| Last Update | May 1, 2026, 3:16 a.m. |