CVE-2025-67683 - Reflected XSS in Quick.Cart

CVE-2025-67683 - Reflected XSS in Quick.Cart

CVE ID : CVE-2025-67683 Published : Jan. 22, 2026, 12:15 p.m. | 1 hour, 46 minutes ago Description : Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary JavaScript execution in the victim’s browser. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 22, 2026
Impact: XSS