Junglewise Threat Intelligence

CVE-2025-14343: Dokuzsoft E-Commerce Product reflected XSS

CVE-2025-14343 · Severity: high · CVSS 7.6 · Published 2026-02-26

Executive brief

Dokuzsoft E-Commerce Product, a platform used for online retail operations, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the web pages seen by other users. If a user clicks a specially crafted link, an attacker could potentially steal session information, perform actions on behalf of the user, or disrupt the availability of the online store. This could lead to unauthorized access to customer accounts or damage to the company's reputation.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Dokuzsoft Technology Ltd. E-Commerce Product through version 10122025. The flaw is rooted in the application's failure to properly neutralize user-supplied input before including it in dynamically generated web pages (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking, unauthorized data access, or impact on service availability as indicated by the high availability impact in the CVSS score.

Affected products

  • Dokuzsoft Technology Ltd. E-Commerce Product through 10122025

Timeline

  • 2026-02-26: advisory: Initial advisory published by USOM/TR-CERT
  • 2026-02-26: disclosed: CVE published to NVD

References