Intel

AIKIDO-2026-11071

drupal/commerce is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)CVE-2026-10769 Published Yesterday

58

Medium Risk

This Affects:

PHPdrupal/commerce
3.3.0 - 3.3.5
Fixed in 3.3.6
Are you affected? Scan for Free

TL;DR

The module doesn't sufficiently sanitize customer comments in the order receipt email template; this could be exploited to achieve Cross-site Scripting (XSS).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your site has Checkout (commerce_checkout) enabled, and the "Comments" checkout pane (id: customer_comments) is explicitly used.

Background info

drupal/commerce is vulnerable to Cross-Site Scripting (XSS) in versions 3.3.0 - 3.3.5.

How to fix this

Upgrade the drupal/commerce library to the patch version.