CVE-2026-10769: Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Core allows Stored XSS. This issue affects Commerce Core versions: from 3.3.0 to 3.3.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal Commerce Coreto a version that resolves this vulnerability.Patch SA-CONTRIB-2026-041
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10769?
CVE-2026-10769 has a medium severity rating of 5.4 according to the CVSS 3.1 standard.
How do I fix CVE-2026-10769?
To fix CVE-2026-10769, upgrade your Drupal Commerce Core to version 3.3.7 or later.
What type of vulnerability is CVE-2026-10769?
CVE-2026-10769 is a Cross-Site Scripting (XSS) vulnerability that allows for Stored XSS attacks.
Which versions of Commerce Core are affected by CVE-2026-10769?
CVE-2026-10769 affects Commerce Core versions from 3.3.0 to 3.3.6.
What is the impact of CVE-2026-10769?
The impact of CVE-2026-10769 includes potential execution of malicious scripts in the context of authenticated user sessions.