Known Vulnerabilities for Commerce by Craftcms
Listed below are 10 of the newest known vulnerabilities associated with "Commerce" by "Craftcms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-39851 json | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mu... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-39689 json | Missing Authorization vulnerability in eshipper eShipper Commerce eshipper-commerce allows Exploiting Incorrectly Configured ... | Not Provided | 2026-04-08 | 2026-04-13 |
| CVE-2026-35407 json | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and author... | Not Provided | 2026-04-08 | 2026-04-10 |
| CVE-2026-35401 json | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can includ... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-33756 json | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batchi... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-33674 json | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation fram... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-33673 json | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Sit... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-32272 json | Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists... | Not Provided | 2026-04-13 | 2026-04-13 |
| CVE-2026-32271 json | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an ... | Not Provided | 2026-04-13 | 2026-04-13 |
| CVE-2026-32270 json | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the Payments... | Not Provided | 2026-04-13 | 2026-04-13 |