
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29177 is a Stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce's Order Details Slideout, classified as Low severity. Malicious JavaScript can be injected via the Shipping Method Name, Order Reference, or Site Name fields, and executes when any user double-clicks an order on the Orders index page to open the details slideout. The vulnerability affects Craft Commerce versions 4.0.0–4.10.1 and 5.0.0–5.5.2 (Composer package craftcms/commerce). It was published on March 9, 2026, with a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 1.9 (Low) (GitHub Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-controlled metadata fields — specifically Shipping Method Name, Order Reference (reference), Site Name, Coupon Code, and Origin — were rendered without HTML encoding in the getMetadata() method of src/elements/Order.php. The fix applied Html::encode() to each of these fields before they were placed into the metadata array rendered in the slideout UI (Patch Commit). Exploitation requires an authenticated attacker with at least low-level privileges (e.g., access to Store Management or order editing), and a separate privileged user must interact with the affected order by double-clicking it on the /admin/commerce/orders index page. Detailed reproduction steps and a concrete PoC payload (<img src=x onerror=alert('XSS_Shipping')>) are publicly documented in the security advisory (GitHub Advisory).
Successful exploitation allows the injected script to execute in the browser of any user who views the affected order's details slideout, operating with that user's session privileges. This can lead to session token theft, unauthorized actions performed on behalf of the victim (such as modifying order data), and limited information disclosure within the Craft Commerce admin panel. Availability is not impacted, and the scope is limited to the administrative interface rather than the public-facing storefront (GitHub Advisory).
A proof-of-concept exploit is publicly available in the official security advisory, including numbered reproduction steps and a concrete XSS payload (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014% (2nd percentile), indicating a low probability of exploitation in the near term. Exploitation requires authenticated access with at least low privileges, limiting the attacker pool.
<img src=x onerror=alert('XSS_Shipping')> in the Name field, then save./admin/commerce/orders) and double-clicks the target order to open the details slideout, the stored payload executes in their browser.<img, <script, onerror=, javascript:)./admin/commerce/orders page.Update Craft Commerce to version 4.10.2 (for the 4.x branch) or 5.5.3 (for the 5.x branch), which apply Html::encode() to all affected metadata fields (GitHub Advisory, Patch Commit). As an interim workaround, restrict access to Store Management and order editing functions to only fully trusted users, and audit existing Shipping Method Names, Order References, Site Names, and Coupon Codes for suspicious JavaScript content. Monitoring order metadata fields for HTML injection patterns is also recommended until patching is complete.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."