MEDIUM
Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions
Published Apr 30, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.24%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.