---
id: CVE-2026-90570
title: >-
  A vulnerability has been found in linlinjava litemall
  1.4.0/1.5.0/1.6.0/1.7.0/1.8.0
summary: >-
  A vulnerability has been found in linlinjava litemall
  1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function
  AdminGoodsService.validate of the file
  litemall-vue/src/views/items/detail/index.vue of the component Product Detail.
  Su…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: linlinjava
product: litemall
affected:
  - litemall 1.4.0
  - litemall 1.5.0
  - litemall 1.6.0
  - litemall 1.7.0
  - litemall 1.8.0
published: '2026-09-13'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:30.560'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90570'
references:
  - url: 'https://gitee.com/linlinjava/litemall/'
    label: cna@vuldb.com
  - url: 'https://gitee.com/linlinjava/litemall/issues/IK5SVR'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90570'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/912674'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403155'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403155/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.00368
epssPercentile: 0.27914
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T14:12:22.655427Z'
ingestedAt: '2026-09-14T15:23:07.469Z'
---

## Overview

A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
