medium · CVSS v3 5.4 · CVSS v4 5.1
CVE-2026-104479
Shopclass versions prior to 6.2.0 allow self‑registered non‑admin users to inject JavaScript into item listing descriptions via the TinyMCE
Overview
Shopclass versions prior to 6.2.0 allow self‑registered non‑admin users to inject JavaScript into item listing descriptions via the TinyMCE editor. The malicious code is stored in ItemActions.php and executes in the site origin for any visitor, enabling a stored XSS attack. This flaw can be exploited by anyone who can create or edit listings.
Description
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.
Impact
The vulnerability compromises confidentiality, integrity, and availability of the web application by allowing attackers to run arbitrary scripts in users’ browsers. Defenders must consider all Shopclass installations that have not applied the 6.2.0 patch or disabled TinyMCE.
Remediation
Apply the official 6.2.0 update or later, or if updating is not possible, disable TinyMCE on the frontend or implement server‑side sanitization of listing descriptions before storage.
Risk context
The CVSS v3 score of 5.4 indicates a medium‑severity risk; with no EPSS data, the threat remains moderate but should be addressed promptly to prevent potential data exfiltration or session hijacking.
Affected products
- Shopclass
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 5.4
- CVSS v4
- 5.1
- EPSS
- —