CVE-2018-10135: Iscripts Eswap

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.

Affected products

Published 2018-04-16. Last modified 2026-06-17.