Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pmgj-gmm4-jh6j | Craft Commerce is vulnerable to SQL Injection in Commerce Inventory Table Sorting |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 10 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The sort[0][direction] and sort[0][sortField] parameters are concatenated directly into an addOrderBy() clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arbitrary SQL queries, potentially leading to a full database compromise. This vulnerability is fixed in 5.5.3. | |
| Title | Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-10T20:12:39.918Z
Reserved: 2026-03-04T14:44:00.713Z
Link: CVE-2026-29174
Updated: 2026-03-10T20:11:48.646Z
Status : Received
Published: 2026-03-10T20:16:38.550
Modified: 2026-03-10T20:16:38.550
Link: CVE-2026-29174
No data.
OpenCVE Enrichment
No data.
Github GHSA