Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wj89-2385-gpx3 | Craft Commerce has stored XSS in Inventory Location Name |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 10 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored XSS vulnerability exists in the Commerce Settings - Inventory Locations page. The Name field is rendered without proper HTML escaping, allowing an attacker to execute arbitrary JavaScript. This XSS triggers when an administrator (or user with product editing permissions) creates or edits a variant product. This vulnerability is fixed in 5.5.3. | |
| Title | Craft Commerce has Stored XSS in Inventory Location Name | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-10T20:12:39.491Z
Reserved: 2026-03-04T14:44:00.713Z
Link: CVE-2026-29176
Updated: 2026-03-10T20:11:42.509Z
Status : Received
Published: 2026-03-10T20:16:38.853
Modified: 2026-03-10T20:16:38.853
Link: CVE-2026-29176
No data.
OpenCVE Enrichment
No data.
Github GHSA