CVE-2026-14633 | kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04 Hidden REST API Endpoint set title/description cross site scripting (GHSA-8q62-q8qx-j49g)
A vulnerability identified as problematic has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument title/description causes cross site scripting.
This vulnerability is tracked as CVE-2026-14633. The attack is possible to be carried out remotely. Moreover, an exploit is present.
This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More