Cross-Site Scripting Vulnerability in Crocoblock JetProductGallery
CVE-2025-54749
6.5MEDIUM
What is CVE-2025-54749?
The Crocoblock JetProductGallery is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user input during web page generation. This issue allows for the possibility of Stored XSS attacks, impacting versions from n/a up to 2.2.0.2. Attackers may exploit this flaw to inject malicious scripts which can compromise user data and site integrity.
Affected Version(s)
JetProductGallery <= 2.2.0.2