Craft Commerce
Vendor:
First CVE: Feb 3, 2026 · Active for under a year
17
Total CVEs
More Total CVEs than 93% of tracked products
17.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Craft Commerce over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2026
5 months ago
Most Recent CVE
Mar 11, 2026
136 days ago
CVE Severity & Scoring
Craft Commerce17 CVEs
88%
12%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (94.1%)
High1 (5.9%)
Unknown0 (0.0%)
User Interaction
None3 (17.6%)
Unknown0 (0.0%)
Required14 (82.4%)
Privileges Required
Low5 (29.4%)
High11 (64.7%)
None1 (5.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29174HIGH Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The sort[0][direct | Mar 10, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-29172HIGH Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables table endpoint. The sort paramet | Mar 10, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-29177MEDIUM Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Craft Commerce Order details. Mali | Mar 10, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-29175MEDIUM Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product Title, Variant Title, and Varian | Mar 10, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-25487MEDIUM Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers t | Feb 3, 2026 | 4.8 | 19 | NO | NO |
CVE-2026-31867MEDIUM Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulnerability exists in Craft Commerce’s cart functiona | Mar 11, 2026 | 4.8 | 18 | NO | NO |
CVE-2026-29176MEDIUM Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored XSS vulnerability exists in the Commerce Settings - Inventory Locations page. The Name field is rend | Mar 10, 2026 | 4.8 | 18 | NO | NO |
CVE-2026-25483MEDIUM Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exists in Craft Commerce’s Order Sta | Feb 3, 2026 | 5.4 | 18 | NO | NO |
CVE-2026-29173MEDIUM Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce O | Mar 10, 2026 | 4.8 | 17 | NO | NO |
CVE-2026-25522MEDIUM Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers t | Feb 3, 2026 | 4.8 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Craft Commerce
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.0 | 8 | 4.9 | 0.3% | 0 | 0 |