Diafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=shop&action=search.
- https://www.exploit-db.com/exploits/51529
- https://github.com/capture0x/My-CVE
- https://github.com/ilqarli27/CVE-2023-37164
- https://github.com/nomi-sec/PoC-in-GitHub