Reflected Cross-Site Scripting Vulnerability in Cradle eCommerce Platform
CVE-2026-3319
5.1MEDIUM
What is CVE-2026-3319?
A reflected cross-site scripting (XSS) vulnerability has been identified in the latest demo version of the Cradle eCommerce platform. This issue allows user-controlled input to be insecurely reflected in the HTML output at the /collection/ endpoint. If exploited, an attacker could execute arbitrary JavaScript code within the context of the affected application, potentially compromising user data and security.
Affected Version(s)
Cradle latest demo version
