Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation of user input by sending a POST request to '/category_product_search', affecting the 'product_name' parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 20 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation of user input by sending a POST request to '/category_product_search', affecting the 'product_name' parameter. | |
| Title | HTML injection in Isshue from Bdtask | |
| First Time appeared |
Bdtask
Bdtask isshue |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:bdtask:isshue:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Bdtask
Bdtask isshue |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-01-20T18:50:40.146Z
Reserved: 2025-04-16T08:38:16.029Z
Link: CVE-2025-40679
Updated: 2026-01-20T18:50:37.611Z
Status : Deferred
Published: 2026-01-20T12:15:49.430
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-40679
No data.
OpenCVE Enrichment
No data.