Back to CVE List

CVE-2026-29175

HIGH SEVERITY

CVSS Score & Metrics

Base Score
5.4 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Vulnerability Description

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product Title, Variant Title, and Variant SKU fields are rendered without proper HTML escaping, allowing an attacker to execute arbitrary JavaScript when any user (including administrators) views the inventory management page. This vulnerability is fixed in 5.5.3.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-79
Source
GitHub
Vendor
composer
Product
craftcms/commerce

External References

Discussion (0)

Add Comment

No comments yet. Be the first!