CVE-2026-25487Active Exploitation(craftcms / craft_commerce)

MEDIUMCVSS 4.8 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch craftcms craft_commerce systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator's browser. This occurs because the Tax Rates 'Name' field in the Store Management section is not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_commerce

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
craft_commerce

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-23: 1Active Exploitation · 2026-03-23: 1Patch / Workaround · 2026-03-23: 103-23
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Cyber Netsec IO@NetSecIO
    Active Exploitation

    📢 CISA KEV UPDATE: Actively exploited flaws in Apple visionOS (CVE-2026-28217), Laravel (CVE-2024-4671), & Craft CMS (CVE-2026-25487) added to catalog. Federal agencies must patch by April 12. All orgs urged to patch NOW! ⚠️ #KEV #CISA 🔗 https://cyber.netsecops.io/articles/cisa-adds-apple-laravel-craft-cms-flaws-to-kev-catalog/?utm_source=twitter&utm_medium=social&utm_campaign=twitter_auto

    Post summary

    CISA reports that Apple visionOS, Laravel, and Craft CMS vulnerabilities are actively being exploited and urges all organizations to patch immediately.

    0000055
    34 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_commerce-craft_cms-
Appcraftcmscraft_commerce4.0.0craft_cms-
Appcraftcmscraft_commerce4.0.0craft_cms-

Explore more