Description
A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scripting. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The flaw exists in the AdminTopicController.validate endpoint of the litemall administrative interface. An attacker can supply crafted input that is reflected into the topic page without proper escaping, resulting in a cross‑site scripting vulnerability that can be triggered remotely.

Affected Systems

Affected software is the litemall e‑commerce platform from linlinjava, specifically versions 1.5.0, 1.6.0, 1.7.0 and 1.8.0. No other vendors or product lines are listed.

Risk and Exploitability

The base score of 4.8 indicates moderate severity. The EPSS score is very low (<1%) and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation at the time of analysis. The attack vector is remote, requiring a specially crafted request to the validate endpoint. Based on the description, unsanitized user input may be reflected into the browser, resulting in script execution when a user views the affected topic page.

Generated by OpenCVE AI on September 15, 2026 at 17:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest litemall release that includes the fixed AdminTopicController.validate endpoint.
  • Sanitize and properly encode any user input in the AdminTopicController.validate endpoint before rendering it in the browser.
  • Restrict access to the administrative interface to authenticated users with appropriate roles and apply a Content Security Policy to mitigate accidental execution of injected scripts.

Generated by OpenCVE AI on September 15, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scripting. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
Title linlinjava litemall Admin Topic index.vue AdminTopicController.validate cross site scripting
First Time appeared Linlinjava
Linlinjava litemall
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:linlinjava:litemall:*:*:*:*:*:*:*:*
Vendors & Products Linlinjava
Linlinjava litemall
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Linlinjava Litemall
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T17:17:58.614Z

Reserved: 2026-09-12T16:03:21.720Z

Link: CVE-2026-90569

cve-icon Vulnrichment

Updated: 2026-09-14T17:17:54.258Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T17:16:57.820

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')