CVE-2024-58296: Phoenixcart CE Phoenix

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.

Affected products

Published 2025-12-11. Last modified 2026-10-02.