🔐 CVE Alert

CVE-2026-3319

UNKNOWN 0.0

Multiple vulnerabilities in Cradle e-commerce

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /collection/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.

CWE CWE-79
Vendor e-commerce
Product cradle
Published May 11, 2026
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for e-commerce cradle

Be the first to know when new unknown vulnerabilities affecting e-commerce cradle are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

e-commerce / Cradle
latest demo version

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-cradle-e-commerce

Credits

Gonzalo Aguilar García (6h4ack)