
CVE-2026-29173 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from … https://www.cve.org/CVERecord?id=CVE-2026-29173
Post summary
CVE-2026-29173 is a stored XSS vulnerability in Craft Commerce before versions 4.10.2 and 5.5.3, which is mitigated by upgrading to those releases.
