CVE-2024-57494

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter.

Published 2025-10-01. Last modified 2026-06-17.