CVE-2026-29177 PUBLISHED

Craft Commerce has Stored XSS in Craft Commerce Order Details Slideout

Assigner: GitHub_M
Reserved: 04.03.2026 Published: 10.03.2026 Updated: 10.03.2026

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Craft Commerce Order details. Malicious JavaScript can be injected via the Shipping Method Name, Order Reference, or Site Name. When a user opens the order details slideout via a double-click on the order index page, the injected payload executes. This vulnerability is fixed in 4.10.2 and 5.5.3.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 1.9

Product Status

Vendor craftcms
Product commerce
Versions
  • Version >= 4.0.0 < 4.10.2 is affected
  • Version >= 5.0.0 < 5.5.3 is affected

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE