CVE-2020-20508: Shopkit Project Shopkit
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.
Affected products
- Shopkit Project Shopkit: version 2.7 only
Published 2021-09-24. Last modified 2026-06-17.