PT-2025-43200 · Xtemos · Woodmart

Published

2025-10-22

·

Updated

2025-11-18

·

CVE-2025-49936

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions xtemos WoodMart versions prior to 8.3.2
Description The software contains a flaw related to improper input handling during web page generation, specifically a DOM-Based Cross-site Scripting issue. This allows for the execution of malicious scripts within the user's browser. The vulnerability exists due to insufficient sanitization of input data, potentially enabling attackers to inject arbitrary code into web pages.
Recommendations Update xtemos WoodMart to version 8.3.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-49936

Affected Products

Woodmart