
CVE-2026-32272 Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and V… https://www.cve.org/CVERecord?id=CVE-2026-32272
Post summary
An SQL injection flaw was disclosed in Craft Commerce's ProductQuery::hasVariant and Variant components affecting versions 5.0.0 through 5.5.4.

