CVE-2026-25488: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-25488 is a stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce, an ecommerce plugin for Craft CMS, titled "Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation." It affects versions 4.0.0-RC1 through 4.10.0 and 5.0.0 through 5.5.1. The vulnerability was published on February 2, 2026, and patched in versions 4.10.1 and 5.5.2. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 6.1 (Medium) (Github Advisory, Craft Commerce Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the failure to HTML-encode user-supplied input in the Tax Categories Name and Description fields before rendering them in the admin panel. The fix, applied in commit fa27333, wraps affected field values with Html::encode() across multiple controllers including TaxCategoriesController.php, ShippingCategoriesController.php, and others (Patch Commit). Exploitation requires an attacker to hold elevated Craft Commerce permissions ("Manage store settings" and "Manage taxes") and control panel access, and requires a separate administrator to visit the Tax Categories page to trigger payload execution. The advisory includes a proof-of-concept demonstrating both basic XSS execution and a privilege escalation chain that elevates the attacker's account to administrator (Craft Commerce Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of any administrator who views the Tax Categories page in the Store Management section. This can lead to session hijacking, credential theft via fake login overlays, unauthorized actions performed on behalf of the victim administrator, and full privilege escalation to administrator-level access. The attack does not directly impact availability or the confidentiality/integrity of the vulnerable system itself, but poses a high integrity risk to subsequent systems (other admin accounts and store settings) (Github Advisory, Craft Commerce Advisory).

Exploitability

A proof-of-concept is publicly documented in the GitHub Security Advisory, demonstrating both basic XSS execution and a privilege escalation payload. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.043% (0.000430), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Obtain required permissions: Acquire a Craft Commerce account with control panel access and the "Manage store settings" and "Manage taxes" permissions — these can be granted to non-administrator users.
  2. Navigate to the vulnerable endpoint: Log in to the admin panel and go to Commerce → Store Management → Tax Categories (/admin/commerce/store-management/primary/taxcategories).
  3. Inject XSS payload: Create a new Tax Category and enter a malicious JavaScript payload (e.g., <script>alert(1)</script> for PoC, or a more sophisticated payload for privilege escalation) in the Name or Description field, then click Save.
  4. Wait for victim interaction: The stored payload executes in the browser of any administrator who subsequently visits the Tax Categories page.
  5. Privilege escalation (advanced): Replace the basic payload with a script that calls the Craft CMS API to elevate the attacker's user ID to administrator, targeting an active elevated session. Alternatively, inject a fake "Session Expired" login modal overlay on the trusted domain to harvest administrator credentials directly.
  6. Achieve objective: With a hijacked session or elevated privileges, perform unauthorized store management actions, exfiltrate data, or maintain persistent access (Craft Commerce Advisory).

Indicators of compromise

  • Logs: Craft CMS admin panel access logs showing requests to /admin/commerce/store-management/primary/taxcategories from unexpected or low-privileged user accounts; log entries for Tax Category creation or modification by non-administrator users.
  • Application Data: Tax Category Name or Description fields in the database containing HTML tags, <script> blocks, JavaScript event handlers (e.g., onerror, onload), or encoded payloads.
  • Network: Outbound requests from administrator browsers to unexpected external domains (e.g., attacker-controlled servers) originating from admin panel page loads; unusual POST requests to Craft CMS user-elevation API endpoints.
  • User Account Changes: Unexpected elevation of non-administrator accounts to administrator role in Craft CMS user management logs (Craft Commerce Advisory).

Mitigation and workarounds

Upgrade Craft Commerce to version 4.10.1 (for the 4.x branch) or 5.5.2 (for the 5.x branch), which apply Html::encode() to all affected fields (Release 4.10.1, Release 5.5.2). As interim mitigations, restrict the "Manage store settings" and "Manage taxes" permissions to only fully trusted administrators, implement Content Security Policy (CSP) headers to limit inline script execution, and audit existing Tax Category fields for suspicious content. Review audit logs for any unauthorized modifications to Tax Category fields prior to patching (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management