๐Ÿ” CVE Alert

CVE-2022-50968

MEDIUM 6.1

uBidAuction 2.0.1 auctions manage Reflected XSS

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
11th

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

CWE CWE-79
Vendor ubidauction
Product ubidauction
Published May 10, 2026
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for ubidauction ubidauction

Be the first to know when new medium vulnerabilities affecting ubidauction ubidauction are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
None
Availability
None

Affected Versions

uBidAuction / uBidAuction
2.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/50693 vulnerability-lab.com: https://www.vulnerability-lab.com/get_content.php?id=2289 apphp.com: https://www.apphp.com/codemarket/items/48/ubidauction-php-classic-and-bid-auctions-script vulncheck.com: https://www.vulncheck.com/advisories/ubidauction-auctions-manage-reflected-xss

Credits

Vulnerability-Lab [Research Team]