Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Commerce — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Commerce, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive overview of security vulnerabilities associated with the Commerce product line, categorized by vendor, specific software versions, and Common Weakness Enumeration (CWE) types. It aggregates a wide spectrum of security issues, ranging from remote code execution and SQL injection flaws to cross-site scripting and authentication bypass vulnerabilities. The data covers advisories issued from the earliest tracked releases through the most recent patches, ensuring a complete historical perspective on the product's security posture over time. Users can utilize this resource to track vendor advisories, understanding the timeline and severity of disclosed security incidents for their specific Commerce deployment. It also allows security professionals and developers to deeply understand the prevalence and impact of specific weakness classes within the application architecture. Additionally, visitors can look up a product’s vulnerability history to assess risk levels, identify recurring issues, and inform patch management strategies. By centralizing this information, the page serves as a critical reference for maintenance teams and security auditors responsible for the integrity of commercial e-commerce systems. The goal is to provide transparent, actionable intelligence that facilitates rapid response to known threats and supports long-term resilience planning for digital retail platforms. This structured approach to vulnerability data helps organizations prioritize remediation efforts based on actual exposure rather than theoretical risk.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-21824 A privilege escalation vulnerability affects HCL Commerce CWE-266 8.8 High2026-07-20
CVE-2026-32272 Craft Commerce: Blind SQL Injection via hasVariant/hasProduct CWE-89 9.8 -2026-04-13
CVE-2026-32271 Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget CWE-89 8.8 -2026-04-13
CVE-2026-32270 Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments CWE-200 5.3 -2026-04-13
CVE-2026-31867 Craft Commerce has a Potential IDOR in Commerce carts CWE-639 8.1AIHighAI2026-03-11
CVE-2026-29177 Craft Commerce has Stored XSS in Craft Commerce Order Details Slideout CWE-79 5.4AIMediumAI2026-03-10
CVE-2026-29176 Craft Commerce has Stored XSS in Inventory Location Name CWE-79 4.8AIMediumAI2026-03-10
CVE-2026-29175 Multiple Stored XSS in Commerce Inventory Page Leading to Session Hijacking CWE-79 6.1AIMediumAI2026-03-10
CVE-2026-29174 Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting CWE-89 8.8AIHighAI2026-03-10
CVE-2026-29173 Craft Commerce has Stored XSS while updating Order Status from Orders Table CWE-79 5.4AIMediumAI2026-03-10
CVE-2026-29172 Craft Commerce has a SQL Injection in Commerce Purchasables Table Sorting CWE-89 8.8AIHighAI2026-03-10
CVE-2026-25522 Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation CWE-79 4.8AIMediumAI2026-02-03
CVE-2026-25490 Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation CWE-79 4.8AIMediumAI2026-02-03
CVE-2026-25489 Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation CWE-79 5.4AIMediumAI2026-02-03
CVE-2026-25488 Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation CWE-79 4.8AIMediumAI2026-02-03
CVE-2026-25487 Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation CWE-79 4.8AIMediumAI2026-02-03
CVE-2026-25486 Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation CWE-79 4.8AIMediumAI2026-02-03
CVE-2026-25485 Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation CWE-79 4.8AIMediumAI2026-02-03
CVE-2026-25484 Craft Commerce has Stored XSS in Product Type Name CWE-79 5.4AIMediumAI2026-02-03
CVE-2026-25483 Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration CWE-79 5.4AIMediumAI2026-02-03
CVE-2026-25482 Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget) CWE-79 5.4AIMediumAI2026-02-03
CVE-2024-23576 HCL Commerce is potentially affected by a denial of service and information disclosure vulnerability 7.1 High2024-05-13
CVE-2021-27741 HCL Commerce 代码问题漏洞 9.1 -2021-08-13

All 23 known CVE vulnerabilities affecting Commerce with full Chinese analysis, references, and POCs where available.