CVE-2020-27478: Simplcommerce
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability found in Simplcommerce v.40734964b0811f3cbaf64b6dac261683d256f961 thru 3103357200c70b4767986544e01b19dbf11505a7 allows a remote attacker to execute arbitrary code via a crafted script to the search bar feature.
Affected products
- Simplcommerce Simplcommerce
Published 2024-04-30. Last modified 2026-06-17.