Medium severity6.1NVD Advisory· Published Oct 29, 2020· Updated Jun 17, 2026
CVE-2020-21266
CVE-2020-21266
Description
Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:broadleafcommerce:broadleaf_commerce:5.1.14-ga:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:broadleafcommerce:broadleaf_commerce:5.1.14-ga:*:*:*:*:*:*:*
- (no CPE)range: <=5.1.14-GA
- Broadleaf/Commercedescription
Patches
Vulnerability mechanics
References
1- www.broadleafcommerce.com/docs/core/5.1/release-notes/5.1.15-ganvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.