PKSA-nrcm-7whq-x868 Security Advisory
-
[MEDIUM] Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation
PKSA-nrcm-7whq-x868 CVE-2026-25490 GHSA-wq2m-r96q-crrf
Affected package: craftcms/commerce
Affected version: >=4.0.0-RC1,<=4.10.0|>=5.0.0-RC1,<=5.5.1
Reported by:
GitHub