CVE-2024-5766: Likeshop

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was found in Likeshop up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin of the component Merchandise Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-267449 was assigned to this vulnerability.

Affected products

  • Likeshop Likeshop: from 2.5.0, up to and including 2.5.7

Published 2024-06-08. Last modified 2026-06-17.