CVE-2026-7172: Stored Cross-Site Scripting (XSS) in TPVEnlanube
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:
CVE-2026-7172: parameter 'Nombre Completo' in the endpoint '/administrator/index.php?option=comvirtuemart&page=admin.userlist'.
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to inject malicious code through the affected parameter. The payload can then execute in the browsers of users who view the stored content.
Which interface should administrators prioritize for review?
Review the user-list administration endpoint at /administrator/index.php?option=com_virtuemart&page=admin.user_list, specifically values submitted through the "Nombre Completo" parameter.
How can I check for possible exploitation?
Inspect user records and related administrative views for unexpected or suspicious content in the "Nombre Completo" field. Because this is stored XSS, suspicious values may execute when an affected user-list page is viewed.