CVE-2026-25482 | Craft CMS up to 4.10.0/5.5.1 Order Status cross site scripting (GHSA-frj9-9rwc-pw9j)
A vulnerability labeled as problematic has been found in Craft CMS up to 4.10.0/5.5.1. This impacts an unknown function of the component Order Status Handler. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-25482. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.