Looking for the vulnerability index of Invicti's legacy products?
AbanteCart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-40626 - Vulnerability Database

AbanteCart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-40626

Medium
Reference: CVE-2025-40626
Title: AbanteCart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Reflected Cross-Site Scripting (XSS) vulnerability inAbanteCart v1.4.0 that could allow an attacker to execute JavaScript code in a victim39s browser by sending the victim a malicious URL. This vulnerability can be exploited to steal sensitive user data such as session cookies or to perform actions on behalf of the user throughquot/about_usXSS_PAYLOADquot.