Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32270

14
FAUCET Score

CVE-2026-32270 is an information disclosure vulnerability affecting Craft Commerce, an ecommerce platform for Craft CMS. The flaw exists in versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, where the PaymentsController::actionPay function exposes sensitive order data to unauthenticated users. When an order number is provided and the email validation fails during anonymous payments, the JSON error response returns the serialized order object containing customer email, shipping address, and billing address information. The vulnerability has a network-based attack vector with low complexity, as it requires only basic knowledge of order numbers to exploit. The impact is limited to confidentiality, exposing personally identifiable information and shipping details without requiring authentication or user interaction. The FAUCET Risk Score of 23.0 out of 100 indicates moderate concern, though the EPSS score of 0.000620000 suggests relatively low exploitation prevalence across the threat landscape. There is no evidence of active exploitation in the wild, no public exploit code appears to be widely available, and community attention remains minimal as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities catalog and its inactive status on hotlist tracking. The issue has been remediated in Craft Commerce versions 4.11.0 and 5.6.0, and affected organizations should prioritize updating to these versions to eliminate the information disclosure risk.

Impacted Technologies

VendorProductVersion(s)CPE
CraftcmsCommerce
>= 4.0.0, < 4.11.0, >= 5.0.0, < 5.6.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

1.7LOW

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 23rd percentile among its peer group of 61 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: craftcms/commerceFixed in: 5.6.0
composerpatch availablevia ghsa
Product: craftcms/commerceFixed in: 4.11.0

Vendor Advisories (1)

composerGHSA-3vxg-x5f8-f5qflow

Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous payments

Apr 14, 2026

References

github.com / craftcms/commerce/commit/48a5d946419964e2af1ac64a8e1acc2a32ca0a08
github.com / craftcms/commerce/releases/tag/4.11.0
github.com / craftcms/commerce/releases/tag/5.6.0
github.com / craftcms/commerce/security/advisories/GHSA-3vxg-x5f8-f5qf