CVE-2026-38939
MEDIUM
NVD
CVSS Score
6.1
Severity
MEDIUM
Published
Apr 30, 2026
Vendor
unknown
Description
Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component