CVE-2026-7171
Stored Cross-Site Scripting (XSS) in TPVEnlanube
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
| CWE | CWE-79 |
| Vendor | tpvenlanube |
| Product | cloud web application |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for tpvenlanube cloud web application
Be the first to know when new unknown vulnerabilities affecting tpvenlanube cloud web application are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TPVEnlanube / Cloud Web application
Actual Web Version
References
Credits
David Padilla Alvarado