CVE-2020-20508: Shopkit Project Shopkit

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.

Affected products

Published 2021-09-24. Last modified 2026-06-17.