CVE-2025-15583

LOW

detronetdip E-commerce 1.0.0 - XSS

Title source: llm
STIX 2.1

Description

A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file utility/function.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.346487
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.346487
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.754033

Scores

CVSS v3 3.5
EPSS 0.0002
EPSS Percentile 6.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
detronetdip/e-commerce 1.0.0
Published Feb 20, 2026
Tracked Since Feb 21, 2026