
CVE-2026-3320 Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in th… https://www.cve.org/CVERecord?id=CVE-2026-3320
Post summary
The text discloses a reflected XSS vulnerability (CVE‑2026‑3320) in the Cradle eCommerce demo, describing the insecure input reflection but providing no further details on exploitation, patching, or active use.
