craftcms/commerce vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55795Mediumcraftcms/commerce: Craft Commerce: Coupon Code Brute-Force via Rate Limit BypassGHSA-78VR-Q6CF-C7P6Mediumcraftcms/commerce: Craft Commerce: Partial Payment Amount Without Lower Bound ValidationCVE-2026-32270Lowcraftcms/commerce: Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous paymentsCVE-2026-32271Highcraftcms/commerce: Craft Commerce has a SQL Injection can lead to Remote Code Execution via TotalRevenue WidgetCVE-2026-32272Highcraftcms/commerce: Craft Commerce hasVariant/hasProduct Blind SQL InjectionCVE-2026-31867Mediumcraftcms/commerce: Craft Commerce: Potential IDOR in Commerce cartsCVE-2026-29177Lowcraftcms/commerce: Craft Commerce has stored XSS in Craft Commerce Order Details SlideoutCVE-2026-29176Mediumcraftcms/commerce: Craft Commerce has stored XSS in Inventory Location NameCVE-2026-29175Highcraftcms/commerce: Craft Commerce has multiple Stored XSS in Commerce Inventory Page, Leading to Session HijackingCVE-2026-29174Highcraftcms/commerce: Craft Commerce is vulnerable to SQL Injection in Commerce Inventory Table SortingCVE-2026-29173Lowcraftcms/commerce: Craft Commerce is Vulnerable to Stored XSS while updating Order Status from Orders TableCVE-2026-29172Highcraftcms/commerce: Craft Commerce is Vulnerable to SQL Injection in Commerce Purchasables Table SortingCVE-2026-25522Mediumcraftcms/commerce: Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege EscalationCVE-2026-25490Mediumcraftcms/commerce: Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege EscalationCVE-2026-25489Mediumcraftcms/commerce: Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege EscalationCVE-2026-25488Mediumcraftcms/commerce: Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege EscalationCVE-2026-25487Mediumcraftcms/commerce: Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege EscalationCVE-2026-25486Mediumcraftcms/commerce: Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege EscalationCVE-2026-25484Mediumcraftcms/commerce: Craft Commerce has Stored XSS in Product Type NameCVE-2026-25483Mediumcraftcms/commerce: Craft Commerce has Stored XSS via Order Status Message with potential database exfiltrationCVE-2026-25482Mediumcraftcms/commerce: Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget)

Stop the waste.
Protect your environment with Kodem.