NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-36766
Summary

Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions.

Publication Date May 1, 2026, 3:16 a.m.
Registration Date May 1, 2026, 4:07 a.m.
Last Update May 1, 2026, 3:16 a.m.
Related information, measures and tools
Common Vulnerabilities List