
CVE-2026-31867 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulnerability exists in Craft Commerce’s … https://www.cve.org/CVERecord?id=CVE-2026-31867
Post summary
The post announces an IDOR vulnerability (CVE‑2026‑31867) in Craft Commerce affecting versions prior to 4.11.0/5.6.0, with a link to the CVE record for further details.
