CVE-2020-29070: Oscommerce

Medium severity, CVSS 4.8. EPSS: 1.2% chance of exploitation in the next 30 days.

osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.

Affected products

Published 2020-11-25. Last modified 2026-06-17.