ard CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

ard vulnerability overview

Aggregates CVE and security vulnerability intelligence across all ard-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting and vendor risk sql injection; exposure may include vendor impact session compromise and vendor impact data exposure in vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-55887 Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output encoding, an attacker can inject malicious JavaScript code that is executed in the context of a user s browser. This can lead to session hijacking, theft of cookies, and other malicious actions performed on behalf of the victim. [email protected] 6.1 0.05% 2025-09-22 2025-10-14
CVE-2025-55888 Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly sanitized or encoded when rendered, allowing script execution in the context of users browsers. This flaw could lead to session hijacking, cookie theft, and other malicious actions. [email protected] 7.3 0.18% 2025-09-22 2025-10-14
CVE-2025-55885 SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php [email protected] 6.3 0.17% 2025-09-22 2025-10-14
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence