Stored XSS Vulnerability in Craft Commerce by Craft CMS
CVE-2026-25487
6.1MEDIUM
What is CVE-2026-25487?
In Craft Commerce, a popular eCommerce platform for Craft CMS, a stored XSS vulnerability exists in the Tax Rates 'Name' field found in the Store Management section. This security flaw allows malicious actors to inject and execute arbitrary JavaScript code in the browser of an administrator, thereby compromising the integrity of the web application. The vulnerability affects versions from 4.0.0-RC1 to 4.10.0 and 5.0.0 to 5.5.1. Users are advised to update to the patched versions 4.10.1 and 5.5.2 to mitigate this risk.
Affected Version(s)
commerce >= 4.0.0-RC1, < 4.10.1 < 4.0.0-RC1, 4.10.1
commerce >= 5.0.0, < 5.5.2 < 5.0.0, 5.5.2
