
CVE-2026-29174 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The … https://www.cve.org/CVERecord?id=CVE-2026-29174
Post summary
The post announces CVE‑2026‑29174 as an SQL injection flaw in Craft Commerce before v5.5.3, indicating the fix is present in that version.
