VDB
Sign up

package

Packagist/craftcms/composer

pkg:packagist/craftcms/composer

MEDIUMPackagist
GHSA-w8gw-qm8p-j9j3· CVE-2026-25485

Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation

Modified: 2/22/2026