Home

Description

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, there is a Stored XSS via Product Type names. The name is not sanitized when displayed in user permissions settings. The vulnerable input (source) is in Commerce (Product Type settings), but the sink is in CMS user permissions settings. This issue has been patched in versions 4.10.1 and 5.5.2.

PUBLISHED Reserved 2026-02-02 | Published 2026-02-03 | Updated 2026-02-04 | Assigner GitHub_M




MEDIUM: 4.8CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

>= 4.0.0-RC1, < 4.10.1
affected

>= 5.0.0, < 5.5.2
affected

References

github.com/...mmerce/security/advisories/GHSA-2h2m-v2mg-656c

github.com/...ommit/7e1dedf06038c8e70dce0187b7048d4ab8ffb75c

github.com/craftcms/commerce/releases/tag/4.10.1

github.com/craftcms/commerce/releases/tag/5.5.2

cve.org (CVE-2026-25484)

nvd.nist.gov (CVE-2026-25484)

Download JSON