Medium severity5.4NVD Advisory· Published Oct 3, 2026
CVE-2026-104479
CVE-2026-104479
Description
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.2.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.