
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25487 is a stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce, an ecommerce plugin for Craft CMS, that allows attackers to execute malicious JavaScript in an administrator's browser. The vulnerability affects versions 4.0.0-RC1 through 4.10.0 and 5.0.0 through 5.5.1. It was disclosed on February 2, 2026, and patched in versions 4.10.1 and 5.5.2. The CVSS v3.1 base score is 4.8 (Medium), while the CVSS v4.0 base score is 6.1 (Medium) (Github Advisory, Craft Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), classified as a stored XSS. The Tax Rates 'Name' field in the Store Management section (/admin/commerce/store-management/primary/taxrates) was rendered in the admin panel without proper HTML encoding — specifically, the value was passed through Craft::t() without wrapping in Html::encode() before being included in table data returned to the browser. The fix (commit fa27333) applied Html::encode() to name and description fields across multiple controllers including TaxRatesController.php, TaxZonesController.php, ShippingCategoriesController.php, and others. Exploitation requires an attacker account with control panel access and permissions to manage store settings and taxes (Craft Advisory, Patch Commit).
Successful exploitation allows an attacker with limited store management permissions to execute arbitrary JavaScript in the browser of any administrator who visits the Tax Rates page. The most severe consequence is privilege escalation: a crafted payload can silently elevate the attacker's account to full administrator status if the victim has an active elevated session. Additionally, the XSS can be weaponized to display a fake 'Session Expired' login overlay on the trusted admin domain, enabling credential theft from administrators (Craft Advisory).
A proof-of-concept is publicly documented in the GitHub Security Advisory, including specific payloads for both basic XSS demonstration and privilege escalation. Exploitation requires high privileges (store settings and tax management permissions) and passive user interaction from an administrator, limiting opportunistic exploitation. The EPSS score is approximately 0.043% (0.000430), indicating low near-term exploitation probability. There is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).
/admin/commerce/store-management/primary/taxrates) and click to create a new tax rate.<script>alert(1)</script> for PoC, or a more sophisticated payload for privilege escalation or credential harvesting). Select or create a required Tax Category./admin/commerce/store-management/primary/taxrates from unusual accounts or at unusual times; API calls to user-elevation endpoints originating from an administrator session shortly after visiting the tax rates page.Name fields containing HTML tags, <script> elements, or JavaScript event handlers (e.g., onerror, onload).Upgrade Craft Commerce to version 4.10.1 (for the v4 branch) or 5.5.2 (for the v5 branch), which apply Html::encode() to all affected name and description fields before rendering in the admin panel. No configuration-based workaround is available; patching is the only remediation. Administrators should also audit existing tax rate names in the database for any suspicious HTML or script content and review recent privilege changes to user accounts (Release 4.10.1, Release 5.5.2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."