Luke Holder
12 exploits
Active since Feb 2026
Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments
Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget
Craftcms Craft Commerce < 4.10.1 - XSS
CVSS 4.8
Craftcms Craft Commerce < 4.10.1 - XSS
CVSS 5.4
Craftcms Craft Commerce < 4.10.1 - XSS
CVSS 4.8
Craftcms Craft Commerce < 4.10.1 - XSS
CVSS 4.8
Craftcms Craft Commerce < 5.5.2 - XSS
CVSS 4.8
Craftcms Craft Commerce < 4.10.1 - XSS
CVSS 4.8
Craftcms Craft Commerce < 4.10.1 - XSS
CVSS 4.8
Craftcms Craft Commerce < 4.10.1 - XSS
CVSS 4.8
Craftcms Craft Commerce < 4.10.1 - XSS
CVSS 4.8
Craftcms Commerce < 5.5.2 - XSS
CVSS 4.8