SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90570

LOW · CVSS 2.4

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability in the affected versions of linlinjava litemall allows for cross-site scripting (XSS) through improper validation in the AdminGoodsService.validate function, specifically within the Product Detail component. This flaw can be exploited remotely, potentially compromising user data and session integrity. Organizations using these versions of litemall should prioritize patching this vulnerability to mitigate the risk of XSS attacks.

CVE
CVE-2026-90570
Severity
LOW
CVSS
2.4
EPSS
N/A
Java

Original NVD Description

A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.