Craft Commerce
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-32270 craftcms/commerce is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.0.0 - 5.5.4 and 4.0.0 - 4.10.2. | 4.0.0 - 4.10.25.0.0 - 5.5.4 | Low |
CVE-2026-32271 craftcms/commerce is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 4.0.0 - 4.10.2 and 5.0.0 - 5.5.4. | 4.0.0 - 4.10.25.0.0 - 5.5.4 | High |
CVE-2026-32272 craftcms/commerce is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 5.0.0 - 5.6.0. | 5.0.0 - 5.6.0 | High |
AIKIDO-2026-10370 craftcms/commerce is vulnerable to SQL Injection in versions 3.0.0 - 4.10.2 and 5.0.0 - 5.5.4. | 3.0.0 - 4.10.25.0.0 - 5.5.4 | High |
CVE-2026-29176 craftcms/commerce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0 - 5.5.2. | 5.0.0 - 5.5.2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.13 | — | — |
dompdf/dompdf Version ~0.8.2 | — | — |
moneyphp/money Version ^3.1.3 | — | — |
dannyvankooten/vat.php Version ^1.1.2 | — | — |
phpoffice/phpspreadsheet Version ^1.4 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant