NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-3319
Summary

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /collection/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.

Publication Date May 12, 2026, 1:17 a.m.
Registration Date May 12, 2026, 4:14 a.m.
Last Update May 12, 2026, 1:17 a.m.
Related information, measures and tools
Common Vulnerabilities List