Security Advisories for craftcms/commerce in packagist
Moderate
about 2 months ago
Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass
packagist
craftcms/commerce
Moderate
about 2 months ago
Craft Commerce: Partial Payment Amount Without Lower Bound Validation
packagist
craftcms/commerce
Low
4 months ago
Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous payments
packagist
craftcms/commerce
High
4 months ago
Craft Commerce has a SQL Injection can lead to Remote Code Execution via TotalRevenue Widget
packagist
craftcms/commerce
High
4 months ago
Craft Commerce hasVariant/hasProduct Blind SQL Injection
packagist
craftcms/commerce
Low
5 months ago
Craft Commerce has stored XSS in Craft Commerce Order Details Slideout
packagist
craftcms/commerce
Moderate
5 months ago
Craft Commerce has stored XSS in Inventory Location Name
packagist
craftcms/commerce
High
5 months ago
Craft Commerce has multiple Stored XSS in Commerce Inventory Page, Leading to Session Hijacking
packagist
craftcms/commerce
High
5 months ago
Craft Commerce is vulnerable to SQL Injection in Commerce Inventory Table Sorting
packagist
craftcms/commerce
Low
5 months ago
Craft Commerce is Vulnerable to Stored XSS while updating Order Status from Orders Table
packagist
craftcms/commerce
High
5 months ago
Craft Commerce is Vulnerable to SQL Injection in Commerce Purchasables Table Sorting
packagist
craftcms/commerce
Moderate
7 months ago
Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation
packagist
craftcms/commerce
Moderate
7 months ago
Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation
packagist
craftcms/commerce
Moderate
7 months ago
Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation
packagist
craftcms/commerce
Moderate
7 months ago
Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation
packagist
craftcms/commerce
Moderate
7 months ago
Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation
packagist
craftcms/commerce
Moderate
7 months ago
Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation
packagist
craftcms/commerce
Moderate
7 months ago
Craft Commerce has Stored XSS in Product Type Name
packagist
craftcms/commerce
Moderate
7 months ago
Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration
packagist
craftcms/commerce
Moderate
7 months ago
Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget)
packagist
craftcms/commerce