MEDIUM
uBidAuction 2.0.1 myAuctions loose Reflected XSS
Published May 10, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.25%
Description
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
Affected products
-
Affected
- 2.0.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| uBidAuction | uBidAuction | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55985 Advisory
- https://www.apphp.com/codemarket/items/48/ubidauction-php-classic-and-bid-auctions-script product
- https://www.exploit-db.com/exploits/50693 exploit
- https://www.vulncheck.com/advisories/ubidauction-myauctions-loose-reflected-xss third-party-advisory
- https://www.vulnerability-lab.com/get_content.php?id=2289 exploit
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 10, 2026
Updated May 24, 2026
Reserved Jan 11, 2026
Link CVE-2022-50964
CISA Vulnrichment
Updated May 11, 2026
Red Hat
No data
GitHub
No data