---
id: CVE-2024-58296
title: >-
  CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the
  currencies administration panel that allows attackers to inject malicious
  scripts
summary: >-
  CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the
  currencies administration panel that allows attackers to inject malicious
  scripts. Attackers can insert XSS payloads in the title field to execute
  arbitrary Ja…
severity: none
cwe:
  - CWE-79
published: '2025-12-11'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58296'
references:
  - url: 'https://demos6.softaculous.com/CE_Phoenixx3r6jqi4kl/admin/currencies.php'
    label: disclosure@vulncheck.com
  - url: 'https://phoenixcart.org/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52015'
    label: disclosure@vulncheck.com
  - url: 'https://www.softaculous.com/apps/ecommerce/CE_Phoenix'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ce-phoenix-v-stored-cross-site-scripting-via-currencies-administration
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00368
epssPercentile: 0.28288
ingestedAt: '2026-10-02T01:05:54.716Z'
---

## Overview

CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
