Vulnerabilities (CVE)

Filtered by vendor Strongshop Subscribe
Filtered by product Strongshop
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-37621 1 Strongshop 1 Strongshop 2025-06-20 N/A 7.2 HIGH
StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.
CVE-2024-37619 1 Strongshop 1 Strongshop 2024-11-21 N/A 6.1 MEDIUM
StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.