216.73.217.22

CVE-2026-3320

· Published 11/05/2026 16:17 · Modified 11/05/2026 16:17

Labels: CVE-2026-3320 2026-05-11CVE-2026-3320CWE-79[email protected]

Essential information

Published
11/05/2026 16:17
Modified
11/05/2026 16:17
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /product/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cradle / ecommerce platform cpe:2.3:a:cradle:ecommerce_platform:*:*:*:*:*:*:*:*

References