CVE-2026-104479
Received Received - Intake

Stored XSS in Shopclass via Item Listing Descriptions

Vulnerability report for CVE-2026-104479, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mindstellar shopclass to 6.2.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in Shopclass versions before 6.2.0. Non-admin users who can self-register can inject malicious JavaScript into item listing descriptions when the frontend TinyMCE editor is enabled. The injected script is saved without proper sanitization and executes when other users view the listing.

Detection Guidance

Check if your Shopclass version is before 6.2.0 by inspecting the version file or admin panel. Look for listings with suspicious JavaScript in descriptions, especially where TinyMCE is enabled. Use browser developer tools to inspect rendered HTML for injected scripts in listing pages.

Impact Analysis

Attackers could steal user session cookies, perform actions on behalf of users, or deface the website. Visitors viewing affected listings may have their browsers compromised or data stolen if the malicious script executes in their session.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations may face compliance violations if user data is compromised through this exploit.

Mitigation Strategies

Upgrade Shopclass to version 6.2.0 or later immediately. If upgrading is not possible, disable the frontend TinyMCE editor in admin settings. Alternatively, implement strict input sanitization for listing descriptions by enabling the new osc_sanitize_html() function or similar measures.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104479. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart