Vulnerabilities > Hikashop > Hikashop > 1.3.6

DATE CVE VULNERABILITY TITLE RISK
2024-10-21 CVE-2024-40746 Cross-site Scripting vulnerability in Hikashop
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product.
network
low complexity
hikashop CWE-79
5.4