CVE-2025-32195
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-32195 is a Cross-site Scripting (XSS) vulnerability affecting Ecwid Shopping Cart by Lightspeed. The flaw, referred to as Stored XSS, arises due to improper neutralization of user inputs during web page generation. Maliciously crafted scripts can be injected and stored in the affected Ecwid Shopping Cart versions from n/a to 7.0. Successful exploitation could lead to various attacks, such as data theft or unauthorized access, putting users at risk. It is highly recommended that Ecwid Shopping Cart users upgrade to the latest patched version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.