craftcms commerce Vulnerabilities
CVE security advisories and vulnerability history for commerce by craftcms.
Last updated
CVE security advisories and vulnerability history for commerce by craftcms.
Last updated
craftcms commerce has 20 published CVE records since 2026, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 8 have a known public exploit. The average CVSS base score across scored CVEs is 6.0.
This page aggregates every publicly disclosed vulnerability (CVE) affecting craftcms commerce, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
How the CVSS severity of craftcms commerce's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of craftcms commerce's CVEs are currently listed in CISA's KEV catalog.
Public exploits
8
8 of craftcms commerce's CVEs have a known public exploit available.
Browse every craftcms commerce version named in a CVE, then pick one to see only the CVEs that affect it.
20 CVEs
The CWE weakness categories most often found in craftcms commerce CVEs. Follow any weakness for its full explanation.
Browse vulnerabilities for other products by craftcms.
Common questions about craftcms commerce vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new craftcms commerce vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.