Home

Description

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored DOM XSS vulnerability exists in the "Recent Orders" dashboard widget. The Order Status Name is rendered via JavaScript string concatenation without proper escaping, allowing script execution when any admin visits the dashboard. This issue has been patched in versions 4.10.1 and 5.5.2.

PUBLISHED Reserved 2026-02-02 | Published 2026-02-03 | Updated 2026-02-04 | Assigner GitHub_M




MEDIUM: 6.2CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

>= 5.0.0, < 5.5.2
affected

>= 4.0.0-RC1, < 4.10.1
affected

References

github.com/...mmerce/security/advisories/GHSA-frj9-9rwc-pw9j

github.com/...ommit/d94d1c9832a47a1c383e375ae87c46c13935ba65

github.com/craftcms/commerce/releases/tag/4.10.1

github.com/craftcms/commerce/releases/tag/5.5.2

cve.org (CVE-2026-25482)

nvd.nist.gov (CVE-2026-25482)

Download JSON