Multiple vulnerabilities in TPVEnlanube
Posted date 28/09/2026
Identificador
INCIBE-2026-668
Importance
3 - Medium
Affected Resources
TPVEnlanube.
Description
INCIBE has coordinated the publication of 3 medium-severity vulnerabilities affecting TPVEnlanube, a software for managing inventory, warehouses, orders, and suppliers. The vulnerabilities were discovered by David Padilla Alvarado.
These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector and CWE vulnerability type for each vulnerability:
- From CVE-2026-7170 to CVE-2026-7172: 4.8 | CVSS:4.0/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X | CWE-79
Solution
There is no reported solution at this time.
Detail
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoints and parameters:
- CVE-2026-7170: parameter 'vendor_store_name' in the endpoint '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'.
- CVE-2026-7171: parameter 'Apellido 1' in the endpoint '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'.
- CVE-2026-7172: parameter 'Nombre Completo' in the endpoint '/administrator/index.php?option=com_virtuemart&page=admin.user_list'.
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
CVE
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-7170 | Media | No | TPVEnlanube |
| CVE-2026-7171 | Media | No | TPVEnlanube |
| CVE-2026-7172 | Media | No | TPVEnlanube |
References list
Etiquetas


