CVE-2026-27539: Welcart E-Commerce

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.

Affected products

  • Welcart Welcart E-Commerce: up to and including 2.11.31

Published 2026-08-13. Last modified 2026-08-14.