Craft Commerce
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10213 craftcms/commerce is vulnerable to SQL Injection in versions 3.0.0 - 4.10.1 and 5.0.0 - 5.5.2. | 3.0.0 - 4.10.15.0.0 - 5.5.2 | High |
AIKIDO-2026-10214 craftcms/commerce is vulnerable to Cross-site Scripting (XSS) in versions 3.0.0 - 4.10.1 and 5.0.0 - 5.5.2. | 3.0.0 - 4.10.15.0.0 - 5.5.2 | Low |
CVE-2026-25490 craftcms/commerce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0-RC1 - 5.5.1 and 4.0.0-RC1 - 4.10.0. | 4.0.0-RC1 - 4.10.05.0.0-RC1 - 5.5.1 | Medium |
CVE-2026-25489 craftcms/commerce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0-RC1 - 5.5.1 and 4.0.0-RC1 - 4.10.0. | 4.0.0-RC1 - 4.10.05.0.0-RC1 - 5.5.1 | Medium |
CVE-2026-25522 craftcms/commerce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0-RC1 - 5.5.1 and 4.0.0-RC1 - 4.10.0. | 4.0.0-RC1 - 4.10.05.0.0-RC1 - 5.5.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.13 | — | — |
dompdf/dompdf Version ~0.8.2 | — | — |
moneyphp/money Version ^3.1.3 | — | — |
dannyvankooten/vat.php Version ^1.1.2 | — | — |
phpoffice/phpspreadsheet Version ^1.4 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant