CVE-2026-25487: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-25487 is a stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce, an ecommerce plugin for Craft CMS, that allows attackers to execute malicious JavaScript in an administrator's browser. The vulnerability affects versions 4.0.0-RC1 through 4.10.0 and 5.0.0 through 5.5.1. It was disclosed on February 2, 2026, and patched in versions 4.10.1 and 5.5.2. The CVSS v3.1 base score is 4.8 (Medium), while the CVSS v4.0 base score is 6.1 (Medium) (Github Advisory, Craft Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), classified as a stored XSS. The Tax Rates 'Name' field in the Store Management section (/admin/commerce/store-management/primary/taxrates) was rendered in the admin panel without proper HTML encoding — specifically, the value was passed through Craft::t() without wrapping in Html::encode() before being included in table data returned to the browser. The fix (commit fa27333) applied Html::encode() to name and description fields across multiple controllers including TaxRatesController.php, TaxZonesController.php, ShippingCategoriesController.php, and others. Exploitation requires an attacker account with control panel access and permissions to manage store settings and taxes (Craft Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker with limited store management permissions to execute arbitrary JavaScript in the browser of any administrator who visits the Tax Rates page. The most severe consequence is privilege escalation: a crafted payload can silently elevate the attacker's account to full administrator status if the victim has an active elevated session. Additionally, the XSS can be weaponized to display a fake 'Session Expired' login overlay on the trusted admin domain, enabling credential theft from administrators (Craft Advisory).

Exploitability

A proof-of-concept is publicly documented in the GitHub Security Advisory, including specific payloads for both basic XSS demonstration and privilege escalation. Exploitation requires high privileges (store settings and tax management permissions) and passive user interaction from an administrator, limiting opportunistic exploitation. The EPSS score is approximately 0.043% (0.000430), indicating low near-term exploitation probability. There is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).

Exploitation steps

  1. Obtain limited admin access: Log in to the Craft CMS admin panel with an account that has the following permissions: Access the control panel, Access Craft Commerce, Manage store settings, and Manage taxes.
  2. Navigate to the vulnerable endpoint: Go to Commerce → Store Management → Tax Rates (/admin/commerce/store-management/primary/taxrates) and click to create a new tax rate.
  3. Inject XSS payload: In the 'Name' field, enter a malicious JavaScript payload (e.g., <script>alert(1)</script> for PoC, or a more sophisticated payload for privilege escalation or credential harvesting). Select or create a required Tax Category.
  4. Save the tax rate: Click Save; the payload is stored in the database and will execute whenever the Tax Rates listing page is rendered in any administrator's browser.
  5. Trigger execution: Wait for or socially engineer an administrator with an active elevated session to visit the Tax Rates page. The stored payload executes in their browser context.
  6. Escalate privileges (optional): Use a payload that calls the Craft CMS API to elevate the attacker's user account to Administrator, replacing the attacker's user ID in the payload. Alternatively, render a fake 'Session Expired' modal to capture the administrator's credentials (Craft Advisory).

Indicators of compromise

  • Logs: Craft CMS admin access logs showing requests to /admin/commerce/store-management/primary/taxrates from unusual accounts or at unusual times; API calls to user-elevation endpoints originating from an administrator session shortly after visiting the tax rates page.
  • Database: Tax rate records in the database with Name fields containing HTML tags, <script> elements, or JavaScript event handlers (e.g., onerror, onload).
  • Network: Outbound HTTP requests from the admin browser to attacker-controlled domains (e.g., for credential exfiltration or XSS beacon callbacks) originating from admin panel page loads.
  • User Account Changes: Unexpected elevation of non-administrator accounts to administrator role in the Craft CMS user management panel, particularly accounts with store management permissions (Craft Advisory).

Mitigation and workarounds

Upgrade Craft Commerce to version 4.10.1 (for the v4 branch) or 5.5.2 (for the v5 branch), which apply Html::encode() to all affected name and description fields before rendering in the admin panel. No configuration-based workaround is available; patching is the only remediation. Administrators should also audit existing tax rate names in the database for any suspicious HTML or script content and review recent privilege changes to user accounts (Release 4.10.1, Release 5.5.2).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management