CVE-2026-4378: Stored XSS in Akıllı Ticaret's E-Commerce Pack
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS.
This issue affects E-Commerce Pack: from 4.5.001 through 28082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which versions should be treated as affected?
E-Commerce Pack versions 4.5.001 through 28082026 are listed as affected.
What does an attacker need to exploit this issue?
The CVSS vector indicates network access, low privileges, and user interaction are required. This suggests an attacker must be able to submit content through a low-privileged account or function and have another user view the stored content.
What is the expected security impact?
The vulnerability is rated medium with a CVSS score of 5.4. It can have low confidentiality and integrity impact, and the scope may extend beyond the vulnerable component; no availability impact is indicated.