Cross-Site Scripting Vulnerability in Dayneks E-Commerce Platform
CVE-2026-5800

6.1MEDIUM

What is CVE-2026-5800?

A cross-site scripting vulnerability exists in the E-Commerce Platform developed by Dayneks Software Industry and Trade Inc. This flaw arises from the improper handling of user input during web page generation, allowing attackers to execute malicious scripts in the context of a user's browser. Consequently, sensitive information may be exposed, and users could be redirected to harmful sites, leading to a compromise of their accounts and data. Despite early notification to the vendor regarding this security issue, no corrective action has been taken to address the vulnerability.

Affected Version(s)

E-Commerce Platform 0 <= 28082026

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ferit Ă–ZNER
.