CVE-2026-29173 | Craft Commerce up to 4.10.2/5.5.3 Order Status cross site scripting (GHSA-mqxf-2998-c6cp)
A vulnerability, which was classified as problematic, was found in Craft Commerce up to 4.10.2/5.5.3. Impacted is an unknown function of the component Order Status Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-29173. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.