Ad

CVE-2026-31867

MEDIUM CVSS 4.0: 6.3 EPSS 0.07%
Updated Mar 17, 2026
Craftcms
Parameter Value
CVSS 6.3 (MEDIUM)
Affected Versions 4.0.0 — 5.6.0
Fixed In 4.11.0
Type CWE-639 (Authorization Bypass)
Vendor Craftcms
Public PoC No

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulnerability exists in Craft Commerce’s cart functionality that allows users to hijack any shopping cart by knowing or guessing its 32-character number. The CartController accepts a user-supplied number parameter to load and modify shopping carts.

No ownership validation is performed - the code only checks if the order exists and is incomplete, not whether the requester has authorization to access it. This vulnerability enables the takeover of shopping sessions and potential exposure of PII. This vulnerability is fixed in 4.11.0 and 5.6.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Craftcms Craft_Commerce
cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*
4.0.0 4.11.0
Craftcms Craft_Commerce
cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*
5.0.0 5.6.0