
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25522 is a stored cross-site scripting (XSS) vulnerability in Craft Commerce, an ecommerce plugin for Craft CMS, that allows attackers to execute malicious JavaScript in an administrator's browser. The flaw affects versions 4.0.0-RC1 through 4.10.0 and 5.0.0 through 5.5.1, and was disclosed on February 2, 2026. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 6.1 (Medium) (Github Advisory, Craft Commerce Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the failure to HTML-encode user-supplied data before rendering it in the admin panel. The Shipping Zone Name and Description fields in the Store Management section passed values directly through Craft::t() without applying Html::encode(), allowing stored JavaScript payloads to execute when the page was rendered. The fix, applied in commit fa27333, added Html::encode() calls across multiple controllers including ShippingZonesController.php, TaxZonesController.php, ShippingCategoriesController.php, and others (Craft Commerce Advisory, Patch Commit). Exploitation requires the attacker to hold high-privilege permissions including "Manage store settings" and "Manage shipping" within the Craft Commerce control panel.
Successful exploitation allows a privileged attacker to inject persistent JavaScript that executes in the browsers of other administrators visiting the Shipping Zones page. The most severe consequence is privilege escalation: a crafted payload can silently elevate the attacker's account to full administrator status if a victim administrator has an active elevated session. Additionally, attackers can deploy fake "Session Expired" login overlays on the trusted admin domain to harvest administrator credentials, enabling account takeover and potential full site compromise (Craft Commerce Advisory).
Proof-of-concept exploit details are publicly documented in the GitHub Security Advisory, including specific steps to reproduce and privilege escalation payloads (Github Advisory). As of the time of disclosure, there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.014% (0.000140), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high-privilege access to the Craft Commerce control panel, which significantly limits the attacker pool.
Commerce → Store Management → Shipping Zones (path: /admin/commerce/store-management/primary/shippingzones).<script>alert(1)</script> for PoC, or a malicious payload for privilege escalation) in the Name or Description field, then save.<script>, onerror=, javascript:) in the Name or Description fields; audit log entries for unexpected privilege changes (user role elevated to Administrator).Upgrade Craft Commerce to version 4.10.1 (for the 4.x branch) or 5.5.2 (for the 5.x branch), which apply Html::encode() to all affected fields (Release 4.10.1, Release 5.5.2). As interim mitigations, restrict the "Manage store settings" and "Manage shipping" permissions to only fully trusted administrators, and implement a Content Security Policy (CSP) header to limit the impact of any XSS execution. Monitor admin panel audit logs for unexpected Shipping Zone modifications or privilege changes.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."