Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h9r9-2pxg-cx9m | Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 18 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms craft Commerce
|
|
| CPEs | cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:* | |
| Vendors & Products |
Craftcms craft Commerce
|
|
| Metrics |
cvssV3_1
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms commerce |
|
| Vendors & Products |
Craftcms
Craftcms commerce |
Tue, 03 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Zone (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2. | |
| Title | Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-03T19:22:34.780Z
Reserved: 2026-02-02T18:21:42.487Z
Link: CVE-2026-25522
Updated: 2026-02-03T19:22:24.431Z
Status : Analyzed
Published: 2026-02-03T19:16:27.290
Modified: 2026-02-18T16:14:46.673
Link: CVE-2026-25522
No data.
OpenCVE Enrichment
Updated: 2026-02-04T12:09:17Z
Github GHSA