Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product Title, Variant Title, and Variant SKU fields are rendered without proper HTML escaping, allowing an attacker to execute arbitrary JavaScript when any user (including administrators) views the inventory management page. This vulnerability is fixed in 5.5.3.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms craft Commerce
|
|
| CPEs | cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:* | |
| Vendors & Products |
Craftcms craft Commerce
|
|
| Metrics |
cvssV3_1
|
Wed, 11 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms commerce |
|
| Vendors & Products |
Craftcms
Craftcms commerce |
Tue, 10 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product Title, Variant Title, and Variant SKU fields are rendered without proper HTML escaping, allowing an attacker to execute arbitrary JavaScript when any user (including administrators) views the inventory management page. This vulnerability is fixed in 5.5.3. | |
| Title | Multiple Stored XSS in Commerce Inventory Page Leading to Session Hijacking | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-10T19:57:36.799Z
Updated: 2026-03-11T14:11:09.100Z
Reserved: 2026-03-04T14:44:00.713Z
Link: CVE-2026-29175
Updated: 2026-03-11T14:10:58.284Z
Status : Analyzed
Published: 2026-03-10T20:16:38.710
Modified: 2026-03-11T16:56:41.960
Link: CVE-2026-29175
No data.
ReportizFlow