
CVE-2026-29176 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored XSS vulnerability exists in the Commerce Settings - Inventory Locations page. The Name… https://www.cve.org/CVERecord?id=CVE-2026-29176
Post summary
The post reports a stored XSS flaw in Craft Commerce’s Inventory Locations page that existed before version 5.5.3, indicating a patch is available, but it does not provide any PoC, exploit code, or evidence of active exploitation.
