CVE-2026-29173: Craft Commerce has Stored XSS while updating Order Status from Orders Table

Published Mar 10, 2026
·
Updated

Summary A stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur.

--- Proof of Concept Required Permissions - Admin access (to edit/create Order Statuses)

Steps to Reproduce 1. Log in with an admin account 2. Navigate to Commerce → Settings → Order Statuses 3. Create a new order status 4. Set the Name field to: html <img src=x onerror="alert('Order Statuses XSS')"> 5. Save the order status 6. Go to Commerce → Orders (make sure you placed any orders) 7. From the left panel, select any Order Status (e.g., New) 8. Select any order from the orders table → Click on the Gear Icon → then click "Update Order Status..." 9. Notice the XSS execution

Other sources

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur. This vulnerability is fixed in 4.10.2 and 5.5.3.

MITRE

Affected Software

4 affected componentsFixes available
composer/craftcms/commerce>=5.0.0<=5.5.2
5.5.3
composer/craftcms/commerce>=4.0.0<=4.10.1
4.10.2
CraftCMS Craft Commerce Craft Cms>=4.0.0<4.10.2
CraftCMS Craft Commerce Craft Cms>=5.0.0<5.5.3

Event History

Mar 10, 2026
Advisory Published
via GitHub·06:23 PM
Data Sourced
via GitHub·06:23 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 22, 58164
Event
via FIRST·06:56 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-29173?

CVE-2026-29173 is classified as a stored XSS vulnerability due to improper escaping when updating the Order Status.

2

How do I fix CVE-2026-29173?

To mitigate CVE-2026-29173, upgrade Craft Commerce to version 5.5.3 or 4.10.2 or later.

3

Which versions of Craft Commerce are affected by CVE-2026-29173?

Craft Commerce versions from 4.0.0 to 4.10.1 and from 5.0.0 to 5.5.2 are affected by CVE-2026-29173.

4

Can CVE-2026-29173 lead to data compromise?

Yes, CVE-2026-29173 can allow an attacker to execute scripts in the context of the user's session, potentially leading to data compromise.

5

What are the implications of CVE-2026-29173 for Craft Commerce users?

Users of affected versions of Craft Commerce could be vulnerable to cross-site scripting attacks, affecting the integrity and security of user data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203