CVE-2026-10769
EUVD-2026-4311510.07.2026, 22:16
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Core allows Stored XSS. This issue affects Commerce Core versions: from 3.3.0 to 3.3.6.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| centarro | commerce_core | 𝑥 < 3.3.6 |
𝑥
= Vulnerable software versions