Reflected Cross-Site Scripting Vulnerability in BeeTienda E-commerce Platform
CVE-2026-4264
5.1MEDIUM
What is CVE-2026-4264?
The BeeTienda e-commerce platform has a reflected Cross-Site Scripting (XSS) vulnerability in its latest demo version. This vulnerability arises from inadequate sanitization of user input in the 'search' parameter of the product list endpoint. Attackers can exploit this flaw by injecting malicious payloads via the 'search' parameter, resulting in these payloads being improperly rendered in the HTML response. Consequently, this allows unauthorized JavaScript code to execute in the browsers of unsuspecting users, potentially leading to data theft, session hijacking, or other malicious activities.
Affected Version(s)
eCommerce Platform 0
