Ecommerce Platform Vulnerability in Craft Commerce by Craft CMS
CVE-2026-32270

1.7LOW

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
13 April 2026

What is CVE-2026-32270?

Craft Commerce, an ecommerce platform for Craft CMS, has a vulnerability in the PaymentsController::actionPay method. This issue allows unauthenticated users to access sensitive order data such as customer email, shipping, and billing addresses when an order number is supplied and an email verification fails during an anonymous payment process. The error response in JSON format inadvertently discloses a serialized order object, compromising sensitive data. This vulnerability has been patched in versions 4.11.0 and 5.6.0.

Affected Version(s)

commerce >= 4.0.0, < 4.11.0 < 4.0.0, 4.11.0

commerce >= 5.0.0, < 5.6.0 < 5.0.0, 5.6.0

References

CVSS V4

Score:
1.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.