CVE-2026-29177 identifies a Stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce versions prior to 4.10.2 and 5.5.3. Malicious JavaScript can be injected into fields such as Shipping Method Name, Order Reference, or Site Name. This payload executes when an authenticated user double-clicks to open order details on the index page. Rated Medium (CVSS 5.4), exploitation requires low privileges and user interaction, potentially impacting confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.10.2CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:* | ||
>= 5.0.0, < 5.5.3CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.