Reflected XSS Vulnerability in AKIN Software E-Commerce Product
CVE-2026-10857
6.1MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 23 June 2026
What is CVE-2026-10857?
A reflected cross-site scripting (XSS) vulnerability exists in AKIN Software's E-Commerce product, affecting versions prior to 1.25.01.06. This flaw allows attackers to inject malicious scripts into web pages, which can be executed by unsuspecting users when they click on manipulated links. This poses a significant risk, potentially leading to session hijacking, data theft, or other malicious actions. It is crucial for users and administrators to update their software to mitigate this vulnerability and safeguard their web applications against exploitation.
Affected Version(s)
e-Commerce 0 < 1.25.01.06
