Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:
CVE-2026-7171: parameter 'Apellido 1' in the endpoint '/administrator/index.php?page=admin.useradd&userid=45&option=comvirtuemart'.
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:
CVE-2026-7172: parameter 'Nombre Completo' in the endpoint '/administrator/index.php?option=comvirtuemart&page=admin.userlist'.
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:
CVE-2026-7170: parameter 'vendorstorename' in the endpoint '/administrator/index.php?pshopmode=admin&page=store.storeadd&option=comvirtuemart&vendorid=[ID]'.
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.