CVE-2024-40746: Hikashop

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend.

Affected products

  • Hikashop Hikashop: before 5.1.1 (fixed in 5.1.1)

Published 2024-10-21. Last modified 2026-06-17.