CVE-2026-25485: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-25485 is a stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce, an ecommerce plugin for Craft CMS, that allows attackers with high privileges to inject malicious JavaScript into an administrator's browser. The vulnerability affects versions 4.0.0-RC1 through 4.10.0 and 5.0.0 through 5.5.1 of the craftcms/commerce Composer package. It was published on February 2, 2026, and patched in versions 4.10.1 and 5.5.2. The CVSS v3.1 base score is 4.8 (Medium), while the CVSS v4.0 base score is 6.2 (Medium) (Github Advisory, Craft Commerce Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a failure to HTML-encode user-supplied data before rendering it in the admin panel. The Shipping Categories Name and Description fields in the Store Management section passed values directly through Craft::t('site', ...) without applying Html::encode(), allowing raw HTML/JavaScript to be stored and later rendered in the browser. The fix (commit fa27333) applied Html::encode() to multiple controllers including ShippingCategoriesController.php, ShippingZonesController.php, TaxCategoriesController.php, and others. Exploitation requires an attacker account with control panel access and the "Manage store settings" and "Manage shipping" permissions (Craft Commerce Advisory, Patch Commit).

Impact

Successful exploitation allows injected JavaScript to execute in an administrator's browser with the admin's session permissions, enabling session hijacking, credential theft via fake login overlays, and unauthorized configuration changes. The stored nature of the XSS means any administrator who views the Shipping Categories page is affected, not just the initial victim. In a privilege escalation scenario, an attacker with limited admin permissions can use the XSS payload to elevate their own account to full administrator status if an elevated session is active, potentially leading to full compromise of the Craft Commerce administration interface (Github Advisory, Craft Commerce Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, including specific payloads for both basic XSS demonstration and privilege escalation. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.025% (7th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Obtain privileged access: Acquire or compromise a Craft Commerce account with control panel access and the "Manage store settings" and "Manage shipping" permissions.
  2. Navigate to the vulnerable endpoint: Log into the admin panel and go to Commerce → Store Management → Shipping Categories (/admin/commerce/store-management/primary/shippingcategories).
  3. Inject the XSS payload: Create a new shipping category and enter a malicious JavaScript payload (e.g., <script>alert(1)</script> for PoC, or a more sophisticated payload for privilege escalation) in the Name or Description field, then save.
  4. Trigger execution: Wait for a target administrator to navigate to the Shipping Categories listing page; the stored payload executes in their browser within the context of the trusted admin domain.
  5. Privilege escalation (advanced): Use the XSS payload to make an authenticated API request that elevates the attacker's account to administrator, or overlay a fake "Session Expired" login modal to capture the victim admin's credentials — both techniques are feasible because the script runs on the trusted domain with the victim's session (Craft Commerce Advisory).

Indicators of compromise

  • Logs: Admin panel access logs showing POST requests to /admin/commerce/store-management/primary/shippingcategories containing HTML/script tags or encoded JavaScript in the name or description parameters.
  • Database: Shipping category records in the database with name or description values containing <script>, javascript:, onerror=, or other XSS indicators.
  • Network: Outbound requests from administrator browsers to unexpected external domains (e.g., attacker-controlled servers) originating from admin panel pages, potentially carrying session tokens or credentials.
  • Logs: Unexpected privilege changes in Craft CMS user logs, such as a non-admin account being elevated to administrator without a corresponding legitimate admin action (Craft Commerce Advisory).

Mitigation and workarounds

Upgrade Craft Commerce to version 4.10.1 (for the 4.x branch) or 5.5.2 (for the 5.x branch), which apply Html::encode() to all affected fields. No configuration-based workaround is available; patching is the only remediation. As interim measures, restrict admin panel access to trusted users only, review existing Shipping Category Name and Description fields for suspicious content, and consider implementing Content Security Policy (CSP) headers to limit XSS impact (Release 4.10.1, Release 5.5.2).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management