Sploitus

CVE-2025-61456

2 known exploits for CVE-2025-61456

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoint. Unsanitized input in the /index parameter is directly reflected back into the response HTML, allowing attackers to execute arbitrary JavaScript in the browser of a user who visits a malicious link or submits a crafted request.

Affected products
Bhabishya-123 E-Commerce
Fix
Available
CVSS 3.1
6.1 MEDIUM
EPSS
0.2% (16th percentile)
Weakness
CWE-79
NVD status
Deferred
Published
2025-10-20
CVE-2025-61456 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2025-61456

Proof-of-concept code and exploit modules indexed by Sploitus