Home/Product/craftcms craft commerce
Product

craftcms craft commerce

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-31867
>= 4.0.0 and < 4.11.0
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulne
4.8MEDIUM
CVE-2026-29177
>= 4.0.0 and < 4.10.2
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerabilit
5.4MEDIUM
CVE-2026-29176
>= 5.0.0 and < 5.5.3
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored XSS vulnerability exists in the Commerce Settings
4.8MEDIUM
CVE-2026-29175
>= 5.0.0 and < 5.5.3
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory
5.4MEDIUM
CVE-2026-29174
>= 5.0.0 and < 5.5.3
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the invent
8.8HIGH
CVE-2026-29173
>= 4.0.0 and < 4.10.2
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tr
4.8MEDIUM
CVE-2026-29172
>= 4.0.0 and < 4.10.2
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in
8.8HIGH
CVE-2026-25522
>= 4.0.0 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS
4.8MEDIUM
CVE-2026-25490
>= 4.0.1 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS
4.8MEDIUM
CVE-2026-25489
>= 4.0.1 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS
4.8MEDIUM
CVE-2026-25488
>= 4.0.1 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS
4.8MEDIUM
CVE-2026-25487
>= 4.0.1 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS
4.8MEDIUM
CVE-2026-25486
>= 5.0.0 and < 5.5.2
Craft Commerce is an ecommerce platform for Craft CMS. From version 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce a
4.8MEDIUM
CVE-2026-25485
>= 4.0.1 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS
4.8MEDIUM
CVE-2026-25484
>= 4.0.1 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, there is a St
4.8MEDIUM
CVE-2026-25483
>= 4.0.1 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS
5.4MEDIUM
CVE-2026-25482
>= 4.0.1 and < 4.10.1
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored DOM
4.8MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin