craftcms/commerce
Packagist20 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting craftcms/commercepage 1 of 1
- CVE-2026-25482MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.10.12026-02-03
vulnerable: 4.0.0 ... 4.9.4 (69 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored DOM XSS vulnerability exists in the "Recent Orders" dashboard widget. The Order Status Name is rendered via JavaS…
- CVE-2026-25483MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.10.12026-02-03
vulnerable: 4.0.0 ... 4.9.4 (69 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exists in Craft Commerce’s Order Status History Message. The message is rendered using the |m…
- CVE-2026-25484MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.10.12026-02-03
vulnerable: 4.0.0 ... 4.9.4 (69 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, there is a Stored XSS via Product Type names. The name is not sanitized when displayed in user permissions settings. The v…
- CVE-2026-25486MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.5.22026-02-03
vulnerable: 5.0.0 ... 5.5.1 (86 versions)
Craft Commerce is an ecommerce platform for Craft CMS. From version 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Ship…
- CVE-2026-25487MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.10.12026-02-03
vulnerable: 4.0.0 ... 4.9.4 (69 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator's browse…
- CVE-2026-25488MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.10.12026-02-03
vulnerable: 4.0.0 ... 4.9.4 (69 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s brow…
- CVE-2026-25489MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.10.12026-02-03
vulnerable: 4.0.0 ... 4.9.4 (69 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s brow…
- CVE-2026-25490MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.10.12026-02-03
vulnerable: 4.0.0 ... 4.9.4 (69 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s brow…
- CVE-2026-25522MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.10.12026-02-03
vulnerable: 4.0.0 ... 4.9.4 (69 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s brow…
- CVE-2026-29172HIGHCVSS 8.8EG 8.8✓ Fixed in 5.5.32026-03-10
vulnerable: 5.0.0 ... 5.5.2 (87 versions)
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables table endpoint. The sort parameter is split by | and the first part (column name) is passed…
- CVE-2026-29173MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.5.32026-03-10
vulnerable: 5.0.0 ... 5.5.2 (87 versions)
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without prop…
- CVE-2026-29174HIGHCVSS 8.8EG 8.8✓ Fixed in 5.5.32026-03-10
vulnerable: 5.0.0 ... 5.5.2 (87 versions)
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The sort[0][direction] and sort[0][sortField] parameters are concatenated dir…
- CVE-2026-29175MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.5.32026-03-10
vulnerable: 5.0.0 ... 5.5.2 (87 versions)
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product Title, Variant Title, and Variant SKU fields are rendered without proper HTML escaping, all…
- CVE-2026-29176MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.5.32026-03-10
vulnerable: 5.0.0 ... 5.5.2 (87 versions)
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored XSS vulnerability exists in the Commerce Settings - Inventory Locations page. The Name field is rendered without proper HTML escaping, allowing an attacker to …
- CVE-2026-29177MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.5.32026-03-10
vulnerable: 5.0.0 ... 5.5.2 (87 versions)
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Craft Commerce Order details. Malicious JavaScript can be injected via the Shipping Method Na…
- CVE-2026-31867MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.11.02026-03-11
vulnerable: 4.0.0 ... 4.9.4 (70 versions)
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulnerability exists in Craft Commerce’s cart functionality that allows users to hijack any shopping cart by kno…
- CVE-2026-32270LOWCVSS 1.7EG 1.7✓ Fixed in 4.11.02026-04-13
vulnerable: 4.0.0 ... 4.9.4 (70 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users when an order number is provided and the …
- CVE-2026-32271HIGHCVSS 7.7EG 7.7✓ Fixed in 5.5.52026-04-13
vulnerable: 5.0.0 ... 5.5.4 (89 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user …
- CVE-2026-32272HIGHCVSS 8.7EG 8.7✓ Fixed in 5.6.02026-04-13
vulnerable: 5.0.0 ... 5.5.4 (89 versions)
Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct properties bypass the input sanitization blocklis…
- CVE-2026-55795MEDIUMEG not assessed✓ Fixed in 4.11.22026-06-19
vulnerable: 4.0.0 ... 4.9.4 (73 versions)
Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass ### Summary The CartController defines a RateLimiter behavior that is only activated when the 'number' POST/GET parameter is explicitly provided. ### Details When an attacke…
Check whether craftcms/commerce is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for craftcms/commerce CVEs against the assets you own.
Start Free Scan →