Stored Cross-Site Scripting Vulnerability in TPVEnlanube by Virtuemart
CVE-2026-7170
4.8MEDIUM
What is CVE-2026-7170?
The TPVEnlanube application contains a stored cross-site scripting vulnerability that affects the 'vendor_store_name' parameter within the endpoint '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'. When exploited by an authenticated attacker, this vulnerability enables the injection of malicious scripts, which can be executed in the browsers of unsuspecting users, compromising their security and privacy.
Affected Version(s)
Cloud Web application Actual Web Version
