rootpwn

medium · CVSS v3 5.4 · CVSS v4 5.1

CVE-2026-104479

Shopclass versions prior to 6.2.0 allow self‑registered non‑admin users to inject JavaScript into item listing descriptions via the TinyMCE

Overview

Shopclass versions prior to 6.2.0 allow self‑registered non‑admin users to inject JavaScript into item listing descriptions via the TinyMCE editor. The malicious code is stored in ItemActions.php and executes in the site origin for any visitor, enabling a stored XSS attack. This flaw can be exploited by anyone who can create or edit listings.

Description

Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.

Impact

The vulnerability compromises confidentiality, integrity, and availability of the web application by allowing attackers to run arbitrary scripts in users’ browsers. Defenders must consider all Shopclass installations that have not applied the 6.2.0 patch or disabled TinyMCE.

Remediation

Apply the official 6.2.0 update or later, or if updating is not possible, disable TinyMCE on the frontend or implement server‑side sanitization of listing descriptions before storage.

Risk context

The CVSS v3 score of 5.4 indicates a medium‑severity risk; with no EPSS data, the threat remains moderate but should be addressed promptly to prevent potential data exfiltration or session hijacking.

Affected products

  • Shopclass

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
5.4
CVSS v4
5.1
EPSS
—

xss stored webapp tinymce shopclass medium

← All CVEs