VDB
Sign up
—

DRUPAL-CONTRIB-2026-041

Details

The module doesn't sufficiently sanitize customer comments in the order receipt email template; this could be exploited to achieve Cross-site Scripting (XSS).

This vulnerability is mitigated by the fact that it only affects installations with Checkout (`commerce_checkout`) enabled, and the "Comments" checkout pane (id: `customer_comments`) is explicitly used, which is disabled by default.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/commerce
Introduced in: 3.3.0Fixed in: 3.3.6

Upgrade drupal/commerce to 3.3.6 or newer (ecosystem packagist:https://packages.drupal.org/8).

References