Ecommerce Platform Vulnerability in Craft Commerce by Craft CMS
CVE-2026-32270
1.7LOW
What is CVE-2026-32270?
Craft Commerce, an ecommerce platform for Craft CMS, has a vulnerability in the PaymentsController::actionPay method. This issue allows unauthenticated users to access sensitive order data such as customer email, shipping, and billing addresses when an order number is supplied and an email verification fails during an anonymous payment process. The error response in JSON format inadvertently discloses a serialized order object, compromising sensitive data. This vulnerability has been patched in versions 4.11.0 and 5.6.0.
Affected Version(s)
commerce >= 4.0.0, < 4.11.0 < 4.0.0, 4.11.0
commerce >= 5.0.0, < 5.6.0 < 5.0.0, 5.6.0
