CVE-2026-32270Disclosure

LOWCVSS 1.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users when an order number is provided and the email check fails during an anonymous payment. The JSON error response includes the serialized order object (order), which contains some sensitive fields such as customer email, shipping address, and billing address. The frontend payment flow's actionPay() retrieves orders by number before authorization is fully enforcedLoad order by number. This issue has been fixed in versions 4.11.0 and 5.6.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-14); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-14: 2Mentions · 2026-04-28: 1Technical Details · 2026-04-14: 204-1404-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure2
2026-04-281
Disclosure1
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-32270: CVE-2026-32270: Information Disclosure in Craft Commerce Payments Controller CVE-2026-32270 is an Information Disclosure vulnerability affecting Craft Commerce, a popular ecommerce extension for the Craft CMS ecosystem. The flaw reside... https://cvereports.com/reports/CVE-2026-32270

    Post summary

    The excerpt announces the existence of CVE‑2026‑32270, an information‑disclosure flaw in Craft Commerce’s payments controller, but does not provide proof‑of‑concept, exploit evidence, or mitigation guidance.

    00000152
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32270 Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some orde… https://www.cve.org/CVERecord?id=CVE-2026-32270

    Post summary

    The post announces CVE-2026-32270, detailing that Craft Commerce’s PaymentsController::actionPay exposes order information in certain versions, but no exploits, patches, or evidence of active use are provided.

    00000123
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32270 Information Disclosure in Craft Commerce PaymentsController Affecting Versions 4.0.0-4.10.2 and 5.0.0-5.5.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32270

    Post summary

    The text announces an information disclosure vulnerability (CVE-2026-32270) affecting certain Craft Commerce versions; it contains technical details but no PoC, exploit, or patch information.

    0000039
    4.0K followersView on X

Explore more