—
DRUPAL-CONTRIB-2026-095
Details
This module enables you to pay for Commerce transactions using Paypal.
The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment.
This vulnerability only affects sites using the Payflow Link payment gateway.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8 / drupal/commerce_paypal
Introduced in:
0 Fixed in: 1.12.0 Upgrade drupal/commerce_paypal to 1.12.0 or newer (ecosystem packagist:https://packages.drupal.org/8).