🔐 CVE Alert

CVE-2026-7170

UNKNOWN 0.0

Stored Cross-Site Scripting (XSS) in TPVEnlanube

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: parameter 'vendor_store_name' in the endpoint  '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.

CWE CWE-79
Vendor tpvenlanube
Product cloud web application
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for tpvenlanube cloud web application

Be the first to know when new unknown vulnerabilities affecting tpvenlanube cloud web application are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TPVEnlanube / Cloud Web application
Actual Web Version

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-tpvenlanube

Credits

David Padilla Alvarado