CVE-2026-3320
Multiple vulnerabilities in Cradle e-commerce
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /product/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.
| CWE | CWE-79 |
| Vendor | e-commerce |
| Product | cradle |
| Published | May 11, 2026 |
| Last Updated | May 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for e-commerce cradle
Be the first to know when new unknown vulnerabilities affecting e-commerce cradle are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
e-commerce / Cradle
latest demo version
References
Credits
Gonzalo Aguilar García (6h4ack)