Back

CVE-2006-0109

Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

Published: Jan 7, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
modular_merchant shopping_cart *

GitHub Security Advisory GHSA-g498-jjc7-9vhw

Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.66%

Top 26% most likely to be exploited

Threat Score 20.5 / 100

Data Sources

NVD EPSS GitHub