CVE-2026-29177: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-29177 is a Stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce's Order Details Slideout, classified as Low severity. Malicious JavaScript can be injected via the Shipping Method Name, Order Reference, or Site Name fields, and executes when any user double-clicks an order on the Orders index page to open the details slideout. The vulnerability affects Craft Commerce versions 4.0.0–4.10.1 and 5.0.0–5.5.2 (Composer package craftcms/commerce). It was published on March 9, 2026, with a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 1.9 (Low) (GitHub Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-controlled metadata fields — specifically Shipping Method Name, Order Reference (reference), Site Name, Coupon Code, and Origin — were rendered without HTML encoding in the getMetadata() method of src/elements/Order.php. The fix applied Html::encode() to each of these fields before they were placed into the metadata array rendered in the slideout UI (Patch Commit). Exploitation requires an authenticated attacker with at least low-level privileges (e.g., access to Store Management or order editing), and a separate privileged user must interact with the affected order by double-clicking it on the /admin/commerce/orders index page. Detailed reproduction steps and a concrete PoC payload (<img src=x onerror=alert('XSS_Shipping')>) are publicly documented in the security advisory (GitHub Advisory).

Impact

Successful exploitation allows the injected script to execute in the browser of any user who views the affected order's details slideout, operating with that user's session privileges. This can lead to session token theft, unauthorized actions performed on behalf of the victim (such as modifying order data), and limited information disclosure within the Craft Commerce admin panel. Availability is not impacted, and the scope is limited to the administrative interface rather than the public-facing storefront (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the official security advisory, including numbered reproduction steps and a concrete XSS payload (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014% (2nd percentile), indicating a low probability of exploitation in the near term. Exploitation requires authenticated access with at least low privileges, limiting the attacker pool.

Exploitation steps

  1. Gain authenticated access: Log in to the Craft Commerce admin panel with an account that has access to Store Management (e.g., a low-privilege store manager account).
  2. Inject payload via Shipping Method: Navigate to Commerce → Store Management → Shipping Methods, click "New Shipping Method", and enter an XSS payload such as <img src=x onerror=alert('XSS_Shipping')> in the Name field, then save.
  3. Associate the malicious shipping method with an order: Place a new order or edit an existing order and set its Shipping Method to the one created in the previous step.
  4. Wait for victim interaction: When a privileged user (e.g., an admin) navigates to the Orders index page (/admin/commerce/orders) and double-clicks the target order to open the details slideout, the stored payload executes in their browser.
  5. Harvest session or perform actions: The executed script can exfiltrate the victim's session cookie, perform authenticated requests on their behalf, or modify order data within the admin panel (GitHub Advisory).

Indicators of compromise

  • Logs: Craft CMS/Commerce access logs showing unusual values in Shipping Method Name, Order Reference, Site Name, Coupon Code, or Origin fields containing HTML tags (e.g., <img, <script, onerror=, javascript:).
  • Application Data: Order or shipping method records in the database containing unsanitized HTML or JavaScript payloads in metadata fields.
  • Network: Outbound requests from admin browsers to unexpected external domains (e.g., for cookie exfiltration) originating from the /admin/commerce/orders page.
  • Browser/Client: Unexpected JavaScript alert dialogs or console errors appearing when opening the order details slideout in the Craft Commerce admin.

Mitigation and workarounds

Update Craft Commerce to version 4.10.2 (for the 4.x branch) or 5.5.3 (for the 5.x branch), which apply Html::encode() to all affected metadata fields (GitHub Advisory, Patch Commit). As an interim workaround, restrict access to Store Management and order editing functions to only fully trusted users, and audit existing Shipping Method Names, Order References, Site Names, and Coupon Codes for suspicious JavaScript content. Monitoring order metadata fields for HTML injection patterns is also recommended until patching is complete.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management