Craft Commerce is Vulnerable to Stored XSS while updating Order Status from Orders Table
Package
Affected versions
>= 4.0.0, <= 4.10.1
>= 5.0.0, <= 5.5.2
Patched versions
4.10.2
5.5.3
Description
Published to the GitHub Advisory Database
Mar 10, 2026
Reviewed
Mar 10, 2026
Published by the National Vulnerability Database
Mar 10, 2026
Last updated
Mar 10, 2026
Summary
A stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur.
Proof of Concept
Required Permissions
Steps to Reproduce
References