Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface
Summary
| CVE | CVE-2026-11975 |
|---|---|
| State | PUBLISHED |
| Assigner | Checkmarx |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-17 13:19:33 UTC |
| Updated | 2026-06-17 17:16:41 UTC |
| Description | Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execute arbitrary JavaScript via the ShortContent and FullContent fields, which are stored without HTML sanitization and rendered unencoded via @Html.Raw() |
Risk And Classification
Primary CVSS: v4.0 6.2 MEDIUM from 596c5446-0ce5-4ba2-aa66-48b3b757a647
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-79 | CWE-79 CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 596c5446-0ce5-4ba2-aa66-48b3b757a647 | Secondary | 6.2 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6.2 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
PassiveConfidentiality
NoneIntegrity
LowAvailability
NoneSub Conf.
HighSub Integrity
HighSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Simplcommerce | SimplCommerce | affected 6142d3b5 git | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/simplcommerce/SimplCommerce/commit/6142d3b5147899e0edb41663ae... | 596c5446-0ce5-4ba2-aa66-48b3b757a647 | github.com | |
| github.com/simplcommerce/SimplCommerce/pull/1151 | 596c5446-0ce5-4ba2-aa66-48b3b757a647 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.