Stored Cross-Site Scripting Vulnerability in Vendure Open-Source Commerce Platform
CVE-2026-63459

8.7HIGH

Key Information:

Vendor

Vendurehq

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-63459?

Vendure, an open-source headless commerce platform, is susceptible to a stored cross-site scripting vulnerability affecting its RichTextDescriptionCell component. This issue arises prior to version 3.6.5 when an administrator-controlled description is assigned to a live element's innerHTML. If a lower-privilege administrator embeds malicious markup in descriptions rendered across various lists, such as Products, Collections, Promotions, Payment Methods, or Shipping Methods, it opens avenues for scripts to execute during administrator sessions. This compromises the integrity of an administrator's session and allows unauthorized actions across different privileges or channels upon viewing affected rows. The vulnerability is addressed in version 3.6.5.

Affected Version(s)

vendure < 3.6.5

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.