craftcms/commerce is vulnerable to Cross-site Scripting (XSS)
36
Low Risk
Affected versions of this package are vulnerable to cross-site scripting (XSS) in the Order element. In the getMetadata() method of the src/elements/Order.php class, several metadata fields such as reference, couponCode, order site, shipping method, and origin are included in the output without proper HTML encoding. This allows attackers to inject malicious HTML or script content that executes in the user’s browser when the metadata is rendered.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/commerce is vulnerable to Cross-site Scripting (XSS) in versions 3.0.0 - 4.10.1 and 5.0.0 - 5.5.2.
Upgrade the craftcms/commerce library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant