Nooncarlett's vulnerability profile centers on its TechStore product, with the observed signal focused on web application input-handling issues, specifically cross-site scripting weaknesses in page-generation logic. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nooncarlett over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63544MEDIUM TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter. | Nov 7, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-63543MEDIUM TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter. | Nov 7, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-66845MEDIUM A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoint reflects the id query parameter directly into the HTML res | Dec 23, 2025 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nooncarlett.
Media articles that mention a CVE ID that affects a product developed by Nooncarlett — matched by CVE ID, not by vendor name.