cleantalk
Vulnerabilities and Security Researches

Email Attachment by Order Status & Products, CVE-2025-49957

CVE, Research URL

CVE-2025-49957

Published on
Oct 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Email Attachment by Order Status &amp; Products email-attachment-by-order-status-products allows Reflected XSS.This issue affects Email Attachment by Order Status &amp; Products: from n/a through <= 1.0.1.
Affected versions
max 1.0.1.
Status
vulnerable