
CVE-2026-29172 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables table endpoint. Th… https://www.cve.org/CVERecord?id=CVE-2026-29172
Post summary
The text identifies CVE-2026-29172 as a SQL Injection vulnerability in Craft Commerce’s purchasables table endpoint, but contains no information on patches, PoC, or active exploitation.
