CVE-2026-25486 is a stored Cross-Site Scripting (XSS) vulnerability affecting Craft Commerce versions 5.0.0 through 5.5.1. An attacker can inject malicious JavaScript into the Shipping Methods Name field, which then executes in an administrator's browser when viewed in the admin panel. This vulnerability has a CVSS score of 4.8 (Medium), indicating a network-based attack requiring high privileges and user interaction, with potential for low impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE. The issue has been resolved in Craft Commerce version 5.5.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.5.2CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.