CVE-2026-31867

Published: Mar 11, 2026 Last Modified: Mar 17, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,3
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 4,8
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: low

Description

AI Translation Available

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulnerability exists in Craft Commerce’s cart functionality that allows users to hijack any shopping cart by knowing or guessing its 32-character number. The CartController accepts a user-supplied number parameter to load and modify shopping carts. No ownership validation is performed - the code only checks if the order exists and is incomplete, not whether the requester has authorization to access it. This vulnerability enables the takeover of shopping sessions and potential exposure of PII. This vulnerability is fixed in 4.11.0 and 5.6.0.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0004
Percentile
0,1th
Updated

EPSS Score Trend (Last 6 Days)

639

Authorization Bypass Through User-Controlled Key

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Craft Commerce by Craftcms

Version Range Affected
From 4.0.0 (inclusive)
To 4.11.0 (exclusive)
cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Craft Commerce by Craftcms

Version Range Affected
From 5.0.0 (inclusive)
To 5.6.0 (exclusive)
cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/craftcms/commerce/pull/4207
https://github.com/craftcms/commerce/security/advisories/GHSA-vff3-pqq8-4cpq