CVE-2026-104479
Last modified
CVE-2026-104479 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing..
Description
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| mindstellar | shopclass | < 6.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-104479?
How severe is CVE-2026-104479?
How do I fix CVE-2026-104479?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104473YesWiki before 4.5.3 contains multiple reflected cross-site …6.1
- CVE-2026-104474OpenLiteSpeed before 1.9.3 contains a local privilege escala…6.7
- CVE-2026-104475IDURAR ERP CRM through 4.1.1 contains a stored cross-site sc…5.4
- CVE-2026-104476Backdrop CMS before 1.35.1 contains an information disclosur…5.9
- CVE-2026-104477Showdown through 2.1.0 contains a cross-site scripting vulne…6.1
- CVE-2026-104478Formwork before 2.3.13 contains a path traversal vulnerabili…7.1
- CVE-2026-104480Discord libdave before 1.2.0 did not reject an MLS Welcome m…9.4
- CVE-2026-1045The Viet contact plugin for WordPress is vulnerable to Store…4.4
- CVE-2026-1046Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to…6.5
- CVE-2026-104606A security flaw has been discovered in itsourcecode Online A…6.3
- CVE-2026-104609A weakness has been identified in onetwothreeneth HospitalMa…7.3
- CVE-2026-104610A security vulnerability has been detected in Tenda HG7, HG9…10
Are you affected by CVE-2026-104479?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
