CVE-2026-29173

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur. This vulnerability is fixed in 4.10.2 and 5.5.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*
cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*

History

11 Mar 2026, 16:55

Type Values Removed Values Added
References () https://github.com/craftcms/commerce/commit/60cdc505c03b6fa2f59715e8c060114b66334afa - () https://github.com/craftcms/commerce/commit/60cdc505c03b6fa2f59715e8c060114b66334afa - Patch
References () https://github.com/craftcms/commerce/commit/a2ea853935ef03297ea1298bdb0d8c55ec5daf7b - () https://github.com/craftcms/commerce/commit/a2ea853935ef03297ea1298bdb0d8c55ec5daf7b - Patch
References () https://github.com/craftcms/commerce/security/advisories/GHSA-mqxf-2998-c6cp - () https://github.com/craftcms/commerce/security/advisories/GHSA-mqxf-2998-c6cp - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
First Time Craftcms
Craftcms craft Commerce
CPE cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*

11 Mar 2026, 13:53

Type Values Removed Values Added
Summary
  • (es) Craft Commerce es una plataforma de comercio electrónico para Craft CMS. Antes de 4.10.2 y 5.5.3, existe una vulnerabilidad XSS almacenada cuando un usuario intenta actualizar el estado del pedido desde la tabla de pedidos de Commerce. El nombre del estado del pedido se renderiza sin el escape adecuado, permitiendo la ejecución de scripts. Esta vulnerabilidad está corregida en 4.10.2 y 5.5.3.

10 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 20:16

Updated : 2026-03-11 16:55


NVD link : CVE-2026-29173

Mitre link : CVE-2026-29173

CVE.ORG link : CVE-2026-29173


JSON object : View

Products Affected

craftcms

  • craft_commerce
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')