VendorsCraft CMScraft_commerceall versions
Vulnerabilities

Craft CMS (Pixel & Tonic) Craft Commerce

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-29174
Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting
Published 2026-03-10 · Analyzed
8.8EPSS 0.005
CVE-2026-29172
Craft Commerce has a SQL Injection in Commerce Purchasables Table Sorting
Published 2026-03-10 · Analyzed
8.8EPSS 0.005
CVE-2026-29175
Multiple Stored XSS in Commerce Inventory Page Leading to Session Hijacking
Published 2026-03-10 · Analyzed
8.6EPSS 0.002
CVE-2026-31867
Craft Commerce has a Potential IDOR in Commerce carts
Published 2026-03-11 · Analyzed
6.3EPSS 0.003
CVE-2026-25482
Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget)
Published 2026-02-03 · Analyzed
6.2EPSS 0.004
CVE-2026-25483
Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration
Published 2026-02-03 · Analyzed
6.2EPSS 0.004
CVE-2026-25485
Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.2EPSS 0.004
CVE-2026-25488
Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25489
Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25490
Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25522
Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25487
Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25486
Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.003
CVE-2026-29177
Craft Commerce has Stored XSS in Craft Commerce Order Details Slideout
Published 2026-03-10 · Analyzed
5.4EPSS 0.002
CVE-2026-29173
Craft Commerce has Stored XSS while updating Order Status from Orders Table
Published 2026-03-10 · Analyzed
4.8EPSS 0.004
CVE-2026-25484
Craft Commerce has Stored XSS in Product Type Name
Published 2026-02-03 · Analyzed
4.8EPSS 0.004
CVE-2026-29176
Craft Commerce has Stored XSS in Inventory Location Name
Published 2026-03-10 · Analyzed
4.8EPSS 0.003