PEEL eCommerce Vulnerabilities and Affected Products
Vulnerabilities associated with PEEL Shopping.
Products
Clear product- PEEL Shopping2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-47897MEDIUM | PEEL Shopping 9.3.0 - 'address' Stored Cross-Site ScriptingPEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.php script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution. CWE-79Jan 23, 2026 | CVSS5.1v4.0 | EPSS0.225% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-47892MEDIUM | PEEL Shopping 9.3.0 - 'Comments/Special Instructions' Stored Cross-Site ScriptingPEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parameter of the purchase page. Attackers can inject malicious JavaScript payloads that will execute when the page is refreshed, potentially allowing client-side script execution. CWE-79Jan 23, 2026 | CVSS5.1v4.0 | EPSS0.225% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |