HIGH
vendurehq
CVE published 2026-09-17
CVE-2026-63459
A stored cross-site scripting vulnerability exists in Vendure, an open-source headless commerce platform, prior to version 3.6.5. The RichTextDescriptionCell component attempts to strip markup by assigning an administrator-controlled description to a live element's innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assignment before textContent [truncated]