CVE-2025-55998

Publication date

2025-09-08 00:00:00

Family

mitre

State

PUBLISHED

Description

A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter