Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. This is fixed in 6.2.6.1-GA.
{ "versions": [ { "introduced": "5.0" }, { "last_affected": "5.2.25-ga" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-33725.json"
[ { "events": [ { "introduced": "6.0" }, { "fixed": "6.2.6.1-ga" } ] } ]