Description
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exists in Craft Commerce’s Order Status History Message. The message is rendered using the |md filter, which permits raw HTML, enabling malicious script execution. If a user has database backup utility permissions (which do not require an elevated session), an attacker can exfiltrate the entire database, including all user credentials, customer PII, order history, and 2FA recovery codes. This issue has been patched in versions 4.10.1 and 5.5.2.
INFO
Published Date :
2026-02-03T18:05:49.411Z
Last Modified :
2026-02-04T16:51:19.008Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-25483 vulnerability.
| Vendors | Products |
|---|---|
| Craftcms |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-25483.