Junglewise Threat Intelligence

CVE-2025-13002: Farktor Software E-Commerce Package XSS

CVE-2025-13002 · Severity: high · CVSS 8.2 · Published 2026-02-12

Technologies: Farktor Software E-Commerce Services Inc. E-Commerce Package. Vendors: Farktor.

Executive brief

Farktor Software's E-Commerce Package, a platform used for managing online retail stores, contains a security vulnerability that allows for cross-site scripting. An attacker could exploit this to inject malicious scripts into the web pages viewed by other users. This could lead to unauthorized actions being performed in a user's session or the defacement of the online storefront.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Farktor Software E-Commerce Package through version 27112025. The flaw stems from improper neutralization of user-supplied input during the generation of web pages (CWE-79). A remote, unauthenticated attacker can exploit this by sending specially crafted input to the application, which is then executed in the context of a victim's browser. While the CNA (TR-CERT) provides a CVSS score of 8.2 with no user interaction required, NVD's analysis suggests a score of 6.1 requiring user interaction. Successful exploitation can allow an attacker to execute arbitrary script code, potentially leading to session hijacking or unauthorized data modification.

Affected products

  • Farktor Software E-Commerce Services Inc. E-Commerce Package through 27112025

Timeline

  • 2026-02-12: disclosed
  • 2026-02-12: advisory

References

Related threats