{"id":"CVE-2025-7567","summary":"ShopXO header.html cross site scripting","details":"A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processing of the file header.html. The manipulation of the argument lang/system_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","modified":"2026-07-15T01:48:55.038686640Z","published":"2025-07-14T03:14:05.401Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7567.json","cna_assigner":"VulDB","cwe_ids":["CWE-79","CWE-94"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7567.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7567"},{"type":"ADVISORY","url":"https://vuldb.com/?id.316265"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.607165"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.607201"},{"type":"REPORT","url":"https://github.com/gongfuxiang/shopxo/issues/89"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.316265"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gongfuxiang/shopxo","events":[{"introduced":"69a2ef51494550ccb5ed9982005fcb56ff286a21"},{"last_affected":"cbea8309ace92a225759886701aa8cb15fe5b6d0"}],"database_specific":{"extracted_events":[{"introduced":"6.0"},{"last_affected":"6.0"},{"introduced":"6.1"},{"last_affected":"6.1"},{"introduced":"6.2"},{"last_affected":"6.2"},{"introduced":"6.3"},{"last_affected":"6.3"},{"introduced":"6.4"},{"last_affected":"6.4"},{"introduced":"6.5.0"},{"last_affected":"6.5.0"}],"source":"AFFECTED_FIELD"}}],"versions":["6.0","6.1","6.2","6.3","6.4","6.5.0","v6.5.0","v6.4.0","v6.3.0","v6.2.0","v6.1.0","v6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7567.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}