VYPR
Medium severity6.1NVD Advisory· Published Mar 19, 2021· Updated Jun 17, 2026

CVE-2020-6578

CVE-2020-6578

Description

Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
zencart/zencartPackagist
< 1.5.7a1.5.7a

Affected products

3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.