Description
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.
Published: 2026-10-02
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Stored XSS
Action: Patch
AI Analysis

Impact

Shopclass before 6.2.0 contains a stored cross‑site scripting flaw that allows any self‑registered non‑admin user to inject JavaScript into the item listing description field when the frontend TinyMCE editor is enabled. The vulnerability arises because ItemActions.php accepts the description without stripping HTML tags, so malicious code is persisted to the database and executed in the browser of any visitor who views the affected listing, potentially leaking cookies, defacing the site, or redirecting users to malicious sites. This failure to properly sanitize user input is a classic input‑validation weakness (CWE‑79) and can compromise confidentiality, integrity, and availability of the site.

Affected Systems

The affected vendor is Mindstellar, product Shopclass. Any installed version before 6.2.0 is vulnerable. The problem exists only when the TinyMCE editor is active and users can submit listing descriptions.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting no widespread exploitation is reported. The attack vector is local to the application: an attacker must register an account on the site and submit a crafted listing description. Once submitted, the injected JavaScript is stored and will run in the context of the site origin whenever the listing is viewed, providing a non‑privileged code‑execution path for cross‑site attacks.

Generated by OpenCVE AI on October 3, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Shopclass to version 6.2.0 or later to apply the vendor patch that sanitizes listing descriptions
  • Disable or remove the TinyMCE editor from the frontend if it is not required, preventing script injections via the editor
  • If a patch is not immediately available, implement input filtering on ItemActions.php to strip or escape HTML tags from listing descriptions to mitigate stored XSS

Generated by OpenCVE AI on October 3, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
Description Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.
Title Shopclass before 6.2.0 Stored XSS via Listing Description Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T23:28:48.624Z

Reserved: 2026-10-02T00:55:58.388Z

Link: CVE-2026-104479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T00:16:36.273

Modified: 2026-10-03T00:16:36.273

Link: CVE-2026-104479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T00:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')