Multiple vulnerabilities in TPVEnlanube

Posted date 28/09/2026
Identificador
INCIBE-2026-668
Importance
3 - Medium
Affected Resources

TPVEnlanube.

Description

INCIBE has coordinated the publication of 3 medium-severity vulnerabilities affecting TPVEnlanube, a software for managing inventory, warehouses, orders, and suppliers. The vulnerabilities were discovered by David Padilla Alvarado.

These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector and CWE vulnerability type for each vulnerability:

  • From CVE-2026-7170 to CVE-2026-7172: 4.8 | CVSS:4.0/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X | CWE-79
Solution

There is no reported solution at this time.

Detail

Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoints and parameters:

  • CVE-2026-7170: parameter 'vendor_store_name' in the endpoint  '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'.
  • CVE-2026-7171: parameter 'Apellido 1' in the endpoint  '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'.
  • CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'.

Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-7170 Media No TPVEnlanube
CVE-2026-7171 Media No TPVEnlanube
CVE-2026-7172 Media No TPVEnlanube
References list