PatchSiren

vendurehq CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH vendurehq CVE published 2026-09-17

CVE-2026-63459

A stored cross-site scripting vulnerability exists in Vendure, an open-source headless commerce platform, prior to version 3.6.5. The RichTextDescriptionCell component attempts to strip markup by assigning an administrator-controlled description to a live element's innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assignment before textContent [truncated]