High severity8.1NVD Advisory· Published Dec 18, 2024· Updated Jun 17, 2026
CVE-2024-56174
CVE-2024-56174
Description
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<5.2.2408+ 2 more
- (no CPE)range: <5.2.2408
- (no CPE)
- cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:*range: <5.2.2408
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.