Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-28814 | A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor declares this as "intended behavior, allowed for authorized administrators". | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 18 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Zen-cart
         Zen-cart zen Cart  | 
|
| Vendors & Products | 
        
        Zen-cart
         Zen-cart zen Cart  | 
Mon, 18 Aug 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Mon, 18 Aug 2025 03:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor declares this as "intended behavior, allowed for authorized administrators". | |
| Title | ZenCart CKEditor cross site scripting | |
| Weaknesses | CWE-79 CWE-94  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV2_0
         
 
 
 
  | 
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-18T13:07:54.670Z
Reserved: 2025-08-17T14:20:29.854Z
Link: CVE-2025-9103
Updated: 2025-08-18T13:07:42.735Z
Status : Awaiting Analysis
Published: 2025-08-18T04:15:39.453
Modified: 2025-08-18T20:16:28.750
Link: CVE-2025-9103
No data.
                        OpenCVE Enrichment
                    Updated: 2025-08-18T21:20:47Z
 EUVD