Reflected Cross-Site Scripting Vulnerability in BeeTienda E-commerce Platform
CVE-2026-4264

5.1MEDIUM

Key Information:

Vendor

Beetienda

Vendor
CVE Published:
9 October 2026

What is CVE-2026-4264?

The BeeTienda e-commerce platform has a reflected Cross-Site Scripting (XSS) vulnerability in its latest demo version. This vulnerability arises from inadequate sanitization of user input in the 'search' parameter of the product list endpoint. Attackers can exploit this flaw by injecting malicious payloads via the 'search' parameter, resulting in these payloads being improperly rendered in the HTML response. Consequently, this allows unauthorized JavaScript code to execute in the browsers of unsuspecting users, potentially leading to data theft, session hijacking, or other malicious activities.

Affected Version(s)

eCommerce Platform 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gonzalo Aguilar GarcĂ­a (6h4ack)
.