Executive brief
Craft Commerce, an e-commerce platform for Craft CMS, contains a security vulnerability in its dashboard reporting tools. An authorized user with access to the control panel can exploit this flaw to execute malicious commands on the underlying server. This could lead to a complete takeover of the website, theft of customer data, or disruption of business operations.
Technical details
A SQL injection vulnerability exists in the TotalRevenue widget of Craft Commerce due to unsanitized widget settings being interpolated into a sprintf-based SQL expression. Because PHP PDO MySQL enables multi-statements by default, an attacker can stack an INSERT statement to inject a maliciously serialized PHP object into the queue table. When the unauthenticated '/actions/queue/run' endpoint is triggered, the yii2-queue PhpSerializer performs an unrestricted unserialize() call. This allows an attacker to use a GuzzleHttp\Cookie\FileCookieJar gadget chain to write a PHP webshell to the webroot, achieving remote code execution as the PHP process user. The vulnerability is patched in versions 4.10.3 and 5.5.5.
Affected products
- Craft CMS Commerce >= 4.0.0, <= 4.10.2, >= 5.0.0, <= 5.5.4
Timeline
- 2026-04-13: advisory: NVD publication date
- 2026-04-14: disclosed: GitHub Advisory published
References
- https://api.github.com/users/RajChowdhury240
- https://github.com/RajChowdhury240
- https://api.github.com/users/RajChowdhury240/gists%7B/gist_id%7D
- https://api.github.com/users/RajChowdhury240/repos
- https://avatars.githubusercontent.com/u/30806882?v=4
- https://api.github.com/users/RajChowdhury240/events%7B/privacy%7D