Junglewise Threat Intelligence

CVE-2026-5800: Dayneks E-Commerce Platform reflected XSS

CVE-2026-5800 · Severity: medium · CVSS 6.1 · Published 2026-08-28

Executive brief

Dayneks E-Commerce Platform, a web-based shopping system, contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through specially crafted URLs. An attacker can trick users into clicking a malicious link, causing their browser to execute unauthorized JavaScript code, potentially stealing session credentials, payment information, or performing unauthorized actions on their behalf.

Technical details

This is a reflected XSS vulnerability arising from improper neutralization of user-supplied input during HTML page generation in the Dayneks E-Commerce Platform. The vulnerability allows an attacker to inject arbitrary JavaScript code into web pages by manipulating URL parameters or form inputs, which is then executed in the victim's browser without proper sanitization or output encoding. The attack is reflected (not stored) and requires user interaction—the victim must click a malicious link or visit an attacker-controlled page that makes the request. An attacker can steal session tokens, intercept sensitive data, or redirect users to phishing sites. The platform is affected through version 28082026; patches or fixes have not yet been announced despite early vendor contact.

Affected products

  • Dayneks E-Commerce Platform through 28082026

Timeline

  • 2026-08-28: disclosed

References