{"id":"CVE-2026-7172","title":"Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:\n\n  *  CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'.\n\n\n\n…","summary":"Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:\n\n  *  CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'.\n\n\n\n…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","cwe":["CWE-79"],"vendor":"TPVEnlanube","product":"Cloud Web application","affected":["cloud_web_application Actual Web Version"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T10:16:45.763","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7172","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-tpvenlanube","label":"cve-coordination@incibe.es"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-28T10:07:17.783Z","slug":"CVE-2026-7172","body":"## Overview\n\nStored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:\n\n  *  CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'.\n\n\n\n\nSuccessful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}