Junglewise Threat Intelligence

CVE-2026-6088: Novadigits StockAgile stored cross-site scripting in API endpoints

CVE-2026-6088 · Severity: info · Published 2026-09-25

Technologies: Novadigits Technologies StockAgile. Vendors: Novadigits Technologies.

Executive brief

StockAgile is inventory and retail management software used by stores, e-commerce sites, and warehouses. A flaw in the API and management panel allows authenticated users to inject malicious JavaScript code through text fields that is then displayed to other users, potentially enabling account takeover or session hijacking of other administrators or staff members.

Technical details

Stored XSS vulnerability in multiple REST endpoints (/inventory/configuration/brands, /inventory/configuration/categories, and others) due to insufficient input validation and output encoding on text fields such as 'code' and 'name'. An authenticated attacker can inject persistent malicious JavaScript that executes in the context of other users' browser sessions when they view the affected pages. No patch is currently available.

Affected products

  • Novadigits technologies StockAgile <UNKNOWN>

Timeline

  • 2026-09-25: disclosed

References

Related threats