CVE-2026-38939

· NIST NVD ↗

Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component

MEDIUM
CVSS severity
6.1
CVSS base score
2026-04-30
Published

CWE codes

CWE-79

Sources