Stored Cross-Site Scripting in PEEL Shopping by PEEL
CVE-2021-47892
Key Information:
- Vendor
Peel Ecommerce
- Status
- Vendor
- CVE Published:
- 23 January 2026
Badges
What is CVE-2021-47892?
PEEL Shopping version 9.3.0 has a stored cross-site scripting vulnerability affecting the 'Comments / Special Instructions' parameter on the purchase page. This vulnerability allows attackers to inject malicious JavaScript payloads that execute when the page is reloaded, potentially leading to the execution of arbitrary client-side scripts. As a result, sensitive user data may be compromised, and the integrity of the web application can be severely affected.
Affected Version(s)
PEEL Shopping 9.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
