Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github."
| Software | From | Fixed in |
|---|---|---|
| zen-cart / zen_cart | 1.6.0 | 1.6.0.x |