Craftcms / Commerce
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-55795 | Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass | MEDIUM | 6.9 | Sep 14, 2026 |
| CVE-2026-32272 | Craft Commerce: Blind SQL Injection via hasVariant/hasProduct | HIGH | 8.7 | Apr 13, 2026 |
| CVE-2026-32271 | Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget | HIGH | 8.7 | Apr 13, 2026 |
| CVE-2026-32270 | Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments | LOW | 1.7 | Apr 13, 2026 |
| CVE-2026-31867 | Craft Commerce has a Potential IDOR in Commerce carts | MEDIUM | 6.3 | Mar 11, 2026 |
| CVE-2026-29177 | Craft Commerce has Stored XSS in Craft Commerce Order Details Slideout | LOW | 1.9 | Mar 10, 2026 |
| CVE-2026-29176 | Craft Commerce has Stored XSS in Inventory Location Name | MEDIUM | 4.8 | Mar 10, 2026 |
| CVE-2026-29175 | Multiple Stored XSS in Commerce Inventory Page Leading to Session Hijacking | HIGH | 8.6 | Mar 10, 2026 |
| CVE-2026-29174 | Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting | HIGH | 8.7 | Mar 10, 2026 |
| CVE-2026-29173 | Craft Commerce has Stored XSS while updating Order Status from Orders Table | LOW | 1.9 | Mar 10, 2026 |
| CVE-2026-29172 | Craft Commerce has a SQL Injection in Commerce Purchasables Table Sorting | HIGH | 8.7 | Mar 10, 2026 |
| CVE-2026-25522 | Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation | MEDIUM | 6.1 | Feb 3, 2026 |
| CVE-2026-25490 | Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation | MEDIUM | 6.1 | Feb 3, 2026 |
| CVE-2026-25489 | Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation | MEDIUM | 6.1 | Feb 3, 2026 |
| CVE-2026-25488 | Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation | MEDIUM | 6.1 | Feb 3, 2026 |
| CVE-2026-25487 | Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation | MEDIUM | 6.1 | Feb 3, 2026 |
| CVE-2026-25486 | Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation | MEDIUM | 6.1 | Feb 3, 2026 |
| CVE-2026-25485 | Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation | MEDIUM | 6.2 | Feb 3, 2026 |
| CVE-2026-25484 | Craft Commerce has Stored XSS in Product Type Name | MEDIUM | 4.8 | Feb 3, 2026 |
| CVE-2026-25483 | Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration | MEDIUM | 6.2 | Feb 3, 2026 |
| CVE-2026-25482 | Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget) | MEDIUM | 6.2 | Feb 3, 2026 |
Showing 1 to 21 of 21 CVEs