Skip to content
Threat Feed

Tag

Ecommerce

6 briefs RSS
high advisory

Stored XSS in Vendure Admin Dashboard via Unsafe HTML Stripping

A stored Cross-Site Scripting (XSS) vulnerability in the Vendure Admin Dashboard allows authenticated administrators to execute arbitrary JavaScript in the context of other users viewing entity lists, leading to potential account takeover.

Vendure Dashboard xss web-vulnerability dashboard ecommerce
2t 1c
critical threat

CVE-2026-2347 - Akilli Commerce E-Commerce Website Authorization Bypass via User-Controlled Key

CVE-2026-2347 describes an authorization bypass vulnerability through a user-controlled key in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website before version 4.5.001, which could lead to session hijacking.

E-Commerce Website cve cve-2026-2347 authorization bypass session hijacking ecommerce
1r 1t 1c
critical advisory

Systempay 1.0 Weak Crypto Allows Payment Signature Forging (CVE-2020-37168)

Systempay 1.0 contains a weak cryptographic implementation vulnerability (CVE-2020-37168) allowing attackers to brute-force the production secret key, forge payment signatures, and manipulate transaction amounts.

Systempay 1.0 cve credential-access ecommerce payment-fraud
2r 1t 1c
high advisory

Adobe Commerce Stored XSS Vulnerability (CVE-2026-34686)

Adobe Commerce versions 2.4.9-beta1 and earlier are susceptible to a stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-34686) that allows low-privileged attackers to inject malicious scripts into form fields, leading to potential account compromise.

Commerce cve-2026-34686 xss stored-xss adobe-commerce web-application ecommerce
2r 2t 1c
high advisory

Adobe Commerce Incorrect Authorization Vulnerability (CVE-2026-34646)

Adobe Commerce versions 2.4.9-beta1 and earlier are vulnerable to an Incorrect Authorization issue (CVE-2026-34646) that allows attackers to bypass security features and gain unauthorized write access without user interaction.

Commerce incorrect authorization security feature bypass ecommerce
2r 2t 1c
high advisory

SourceCodester E-Commerce Site SQL Injection Vulnerability (CVE-2026-4613)

A remote SQL injection vulnerability (CVE-2026-4613) exists in SourceCodester E-Commerce Site 1.0 within the /products.php file due to improper input sanitization of the 'Search' argument, potentially allowing attackers to read or modify sensitive database information.

sql-injection web-application ecommerce cve-2026-4613
2r 1t