VendorsCraft CMScraft_commerce4.0.0
Vulnerabilities

Craft CMS (Pixel & Tonic) Craft Commerce 4.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-25482
Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget)
Published 2026-02-03 · Analyzed
6.2EPSS 0.004
CVE-2026-25483
Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration
Published 2026-02-03 · Analyzed
6.2EPSS 0.004
CVE-2026-25485
Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.2EPSS 0.004
CVE-2026-25487
Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25488
Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25489
Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25490
Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation
Published 2026-02-03 · Analyzed
6.1EPSS 0.004
CVE-2026-25484
Craft Commerce has Stored XSS in Product Type Name
Published 2026-02-03 · Analyzed
4.8EPSS 0.004