Description
Reflected Cross-Site Scripting (XSS) on the BeeTienda e-commerce platform, specifically in the latest demo version. The incident occurs due to a lack of proper sanitization of user input data in the 'search' parameter of the product list endpoint. When malicious payloads are transmitted via the 'search' parameter, they are displayed insecurely in the HTML response, allowing for the arbitrary execution of JavaScript code in the victim's browser.
Published: 2026-10-09
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (arbitrary JavaScript execution in victim browsers)
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw caused by the omission of proper sanitization of the 'search' parameter in the product list endpoint. When an attacker sends a malicious payload via this parameter, the data is returned directly in the HTML response, allowing arbitrary JavaScript execution in the victim's browser. Based on the description, it is inferred that this could facilitate session hijacking, defacement, or phishing attacks against users who visit the compromised page.

Affected Systems

The flaw resides in the BeeTienda eCommerce Platform, specifically in the latest publicly available demo version. No precise release numbers are provided, and the issue has only been confirmed in the demo deployment. Consequently, any instance of BeeTienda that exposes the same search endpoint without proper input handling is potentially vulnerable.

Risk and Exploitability

The CVSS base score of 5.1 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. Because exploitation requires only a crafted query string, an unauthenticated attacker can easily trigger the flaw, but the impact is confined to the client’s browser context and does not affect the server state. The likely attack vector involves manipulating the search parameter and prompting a user to visit the malformed URL. There is no solution reported at this moment.

Generated by OpenCVE AI on October 9, 2026 at 11:29 UTC.

Remediation

Vendor Solution

There is no solution reported at this moment.


OpenCVE Recommended Actions

  • Configure the application to properly sanitize and encode user input for the 'search' parameter in the product list endpoint.
  • Deploy a Web Application Firewall or security plug‑in that blocks suspicious script payloads entering the site.
  • Add a Content‑Security‑Policy header that disallows inline scripts and restricts script sources (e.g., `default-src 'self'; script-src 'self';`).

Generated by OpenCVE AI on October 9, 2026 at 11:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description Reflected Cross-Site Scripting (XSS) on the BeeTienda e-commerce platform, specifically in the latest demo version. The incident occurs due to a lack of proper sanitization of user input data in the 'search' parameter of the product list endpoint. When malicious payloads are transmitted via the 'search' parameter, they are displayed insecurely in the HTML response, allowing for the arbitrary execution of JavaScript code in the victim's browser.
Title Reflected Cross-Site Scripting in BeeTienda eCommerce platform
First Time appeared Beetienda
Beetienda ecommerce Platform
Weaknesses CWE-79
CPEs cpe:2.3:a:beetienda:ecommerce_platform:*:*:*:*:*:*:*:*
Vendors & Products Beetienda
Beetienda ecommerce Platform
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Beetienda Ecommerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-09T17:52:00.240Z

Reserved: 2026-03-16T12:00:08.257Z

Link: CVE-2026-4264

cve-icon Vulnrichment

Updated: 2026-10-09T17:51:55.593Z

cve-icon NVD

Status : Deferred

Published: 2026-10-09T08:16:55.300

Modified: 2026-10-09T18:17:08.400

Link: CVE-2026-4264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')