NA - CVE-2025-22270 - An attacker with access to the Administration...
An attacker with access to the Administration panel, specifically the "Role Management" tab, can inject code by adding a new role in the "name" field. It should be noted, however, that the risk of...
NA - CVE-2025-22271 - The application or its infrastructure allows...
The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For" header. Thus, the action logging mechanism in the application loses...
In the "/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg" endpoint, it is possible to inject code in the "modalDlgMsgInternal" parameter via POST, which is then executed in the browser. The risk...
NA - CVE-2025-22273 - Application does not limit the number or...
Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the "/EPMUI/VfManager.asmx/ChangePassword" endpoint it is possible to perform a...
NA - CVE-2025-22274 - It is possible to inject HTML code into the...
It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page. This issue affects CyberArk Endpoint Privilege Manager in SaaS version...
NA - CVE-2025-1746 - Cross-Site Scripting vulnerability in OpenCart...
Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a...
NA - CVE-2025-1747 - HTML injection vulnerabilities in OpenCart...
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and...
NA - CVE-2025-1748 - HTML injection vulnerabilities in OpenCart...
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and...
NA - CVE-2025-1749 - HTML injection vulnerabilities in OpenCart...
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and...
NA - CVE-2025-1776 - Cross-Site Scripting (XSS) vulnerability in...
Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to execute arbitrary code via the ‘query’ parameter in...