Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur. This vulnerability is fixed in 4.10.2 and 5.5.3.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms craft Commerce
|
|
| CPEs | cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:* | |
| Vendors & Products |
Craftcms craft Commerce
|
|
| Metrics |
cvssV3_1
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms commerce |
|
| Vendors & Products |
Craftcms
Craftcms commerce |
Tue, 10 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur. This vulnerability is fixed in 4.10.2 and 5.5.3. | |
| Title | Craft Commerce has Stored XSS while updating Order Status from Orders Table | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-10T19:54:25.064Z
Updated: 2026-03-10T20:12:40.044Z
Reserved: 2026-03-04T14:44:00.712Z
Link: CVE-2026-29173
Updated: 2026-03-10T20:11:50.683Z
Status : Analyzed
Published: 2026-03-10T20:16:38.383
Modified: 2026-03-11T16:55:37.987
Link: CVE-2026-29173
No data.
ReportizFlow