CVE-2020-37003 MEDIUM

CVE-2020-37003: Sellacious eCommerce 4.6 - Persistent Cross-Site Scripting

Vendor Sellacious
Product Sellacious eCommerce
Weakness CWE-79 · XSS
Published January 30, 2026
Last update May 14, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module that allows attackers to inject malicious scripts. Attackers can exploit multiple address input fields like full name, company, and address to execute persistent script code that can hijack user sessions and manipulate application modules.

Key dates

02Disclosure timeline

January 30, 2026 CVE published
May 14, 2026 Record updated