Cross Site Scripting Vulnerability in mvc-ecommerce by Andrew Tch
CVE-2026-38939

6.1MEDIUM

Key Information:

Vendor

Andrew Tch

Vendor
CVE Published:
30 April 2026

What is CVE-2026-38939?

A Cross Site Scripting (XSS) vulnerability exists in the mvc-ecommerce product version 1.0, developed by Andrew Tch. This vulnerability allows remote attackers to execute arbitrary code by injecting malicious scripts through the product_catalogue.php component. Successful exploitation could lead to unauthorized access to sensitive information, which poses significant risks to users and their data. It is crucial for affected users to apply recommended patches to mitigate potential security threats.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.