Luke Holder
12 exploits
Active since Feb 2026
Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments
Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget
Craft Commerce 4.0.0-RC1-4.10.0 and 5.0.0-5.5.1 - Stored Cross-Site Scripting in Recent Orders Dashboard Widget
CVSS 4.8
Craft Commerce 4.0.0-RC1-4.10.0 and 5.0.0-5.5.1 - Stored Cross-Site Scripting in Order Status History Message
CVSS 5.4
Craft Commerce 4.0.0-RC1-4.10.0 and 5.0.0-5.5.1 - Stored Cross-Site Scripting via Product Type Name
CVSS 4.8
Craft Commerce 4.0.0-RC1-4.10.0 and 5.0.0-5.5.1 - Stored Cross-Site Scripting in Shipping Categories
CVSS 4.8
Craft Commerce 5.0.0-5.5.1 - Stored Cross-Site Scripting in Shipping Methods Name Field
CVSS 4.8
Craft Commerce 4.0.0-RC1-4.10.0 and 5.0.0-5.5.1 - Stored Cross-Site Scripting in Tax Rates Name Field
CVSS 4.8
Craft Commerce 4.0.0-RC1-4.10.0 & 5.0.0-5.5.1 - Stored XSS in Tax Categories
CVSS 4.8
Craft Commerce 4.0.0-RC1-4.10.0 and 5.0.0-5.5.1 - Stored Cross-Site Scripting in Tax Zone Name & Description Fields
CVSS 4.8
Craft Commerce 4.0.0-RC1-4.10.0 & 5.0.0-5.5.1 - Stored XSS in Inventory Locations Address Line 1
CVSS 4.8
Craft Commerce 4.0.0-4.10.0 and 5.0.0-5.5.1 - Stored Cross-Site Scripting in Shipping Zone Name and Description Fields
CVSS 4.8