Q2w3 operates a focused e-commerce platform centered on its Post Order product, a web application handling order management and customer interactions. The observed vulnerability exposure aligns with typical web application attack surfaces, concentrating on cross-site scripting and input-handling defects characteristic of browser-facing order-processing systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Q2w3 over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47521MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Bond, AndreSC Q2W3 Post Order allows Reflected XSS.This issue affects Q2W3 | Nov 30, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Q2w3.
Media articles that mention a CVE ID that affects a product developed by Q2w3 — matched by CVE ID, not by vendor name.