CVE Database
/

CVE-2026-25484

Back to search

CVE-2026-25484

Published: Feb 3, 2026

Modified: Feb 4, 2026

PUBLISHED

Description

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, there is a Stored XSS via Product Type names. The name is not sanitized when displayed in user permissions settings. The vulnerable input (source) is in Commerce (Product Type settings), but the sink is in CMS user permissions settings. This issue has been patched in versions 4.10.1 and 5.5.2.

VendorProductVersions

craftcms

commerce

affected
>= 4.0.0-RC1, < 4.10.1
affected
>= 5.0.0, < 5.5.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now