Xingfuggz · Baykeshop · CVE-2026-3041
**Name of the Vulnerable Software and Affected Versions**
xingfuggz BaykeShop versions up to 1.3.20
**Description**
A security issue exists in xingfuggz BaykeShop, specifically within the Article Sidebar Module. Manipulation of the `sidebar.content` argument in the file `src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html` can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed.
**Recommendations**
Versions prior to 1.3.20 should be updated. As a temporary workaround, consider restricting or disabling the Article Sidebar Module until a fix is available.