CVE-2020-21266: Broadleafcommerce Broadleaf Commerce

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.

Affected products

Published 2020-10-29. Last modified 2026-06-17.