Medium severity4.8OSV Advisory· Published Feb 3, 2026· Updated Jun 17, 2026
CVE-2026-25522
CVE-2026-25522
Description
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Zone (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
craftcms/commercePackagist | >= 5.0.0-RC1, < 5.5.2 | 5.5.2 |
craftcms/commercePackagist | >= 4.0.0-RC1, < 4.10.1 | 4.10.1 |
Affected products
3- cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*Range: >=4.0.0,<4.10.1
Patches
Vulnerability mechanics
References
6- github.com/craftcms/commerce/commit/fa273330807807d05b564d37c88654cd772839eenvdPatchWEB
- github.com/craftcms/commerce/security/advisories/GHSA-h9r9-2pxg-cx9mnvdExploitPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-h9r9-2pxg-cx9mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-25522ghsaADVISORY
- github.com/craftcms/commerce/releases/tag/4.10.1nvdProductRelease NotesWEB
- github.com/craftcms/commerce/releases/tag/5.5.2nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.