CVE-2026-32270 is an information disclosure vulnerability affecting Craft Commerce, an ecommerce platform for Craft CMS. The flaw exists in versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, where the PaymentsController::actionPay function exposes sensitive order data to unauthenticated users. When an order number is provided and the email validation fails during anonymous payments, the JSON error response returns the serialized order object containing customer email, shipping address, and billing address information. The vulnerability has a network-based attack vector with low complexity, as it requires only basic knowledge of order numbers to exploit. The impact is limited to confidentiality, exposing personally identifiable information and shipping details without requiring authentication or user interaction. The FAUCET Risk Score of 23.0 out of 100 indicates moderate concern, though the EPSS score of 0.000620000 suggests relatively low exploitation prevalence across the threat landscape. There is no evidence of active exploitation in the wild, no public exploit code appears to be widely available, and community attention remains minimal as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities catalog and its inactive status on hotlist tracking. The issue has been remediated in Craft Commerce versions 4.11.0 and 5.6.0, and affected organizations should prioritize updating to these versions to eliminate the information disclosure risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Craftcms | Commerce | >= 4.0.0, < 4.11.0, >= 5.0.0, < 5.6.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.