Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v585-mf6r-rqrc | Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation |
Tue, 10 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms craft Commerce
|
|
| CPEs | cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:* cpe:2.3:a:craftcms:craft_commerce:4.0.0:-:*:*:*:craft_cms:*:* cpe:2.3:a:craftcms:craft_commerce:4.0.0:rc1:*:*:*:craft_cms:*:* |
|
| Vendors & Products |
Craftcms craft Commerce
|
|
| Metrics |
cvssV3_1
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms commerce |
|
| Vendors & Products |
Craftcms
Craftcms commerce |
Tue, 03 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Name & Description fields in Tax Zones are not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2. | |
| Title | Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-03T20:34:09.676Z
Reserved: 2026-02-02T16:31:35.823Z
Link: CVE-2026-25489
Updated: 2026-02-03T20:32:06.758Z
Status : Analyzed
Published: 2026-02-03T19:16:26.667
Modified: 2026-02-10T18:08:57.537
Link: CVE-2026-25489
No data.
OpenCVE Enrichment
Updated: 2026-04-18T14:15:04Z
Github GHSA