{"api_version":"v1","generated_at":"2026-10-07T00:30:00+00:00","product":{"cve_count":21,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-craftcms-commerce-1cb200ef3f7e","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"commerce","next_cursor":null,"observations":[{"affected":"commerce: >= 4.0.0, < 4.11.2, >= 5.0.0, < 5.6.5","affected_versions_present":true,"cve_id":"CVE-2026-55795","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55795","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T20:06:54.939Z","patch_url":"","primary_source":"","published":"2026-09-14T15:55:14.000Z"},{"affected":">= 5.0.0 < 5.6.0","affected_versions_present":true,"cve_id":"CVE-2026-32272","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32272","fixed":"5.6.0.","last_modified":"2026-04-14T16:28:47.197Z","patch_url":"https://github.com/craftcms/commerce/security/advisories/GHSA-r54v-qq87-px5r","primary_source":"","published":"2026-04-13T20:25:50.420Z"},{"affected":">= 4.0.0, < 4.10.3; >= 5.0.0, < 5.5.5","affected_versions_present":true,"cve_id":"CVE-2026-32271","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32271","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-16T13:26:40.649Z","patch_url":"","primary_source":"","published":"2026-04-13T20:19:19.486Z"},{"affected":">= 4.0.0, < 4.11.0; >= 5.0.0, < 5.6.0","affected_versions_present":true,"cve_id":"CVE-2026-32270","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32270","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-14T15:25:04.635Z","patch_url":"","primary_source":"","published":"2026-04-13T20:08:05.032Z"},{"affected":">= 4.0.0, < 4.11.0; >= 5.0.0, < 5.6.0","affected_versions_present":true,"cve_id":"CVE-2026-31867","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31867","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-12T13:49:48.940Z","patch_url":"https://github.com/craftcms/commerce/security/advisories/GHSA-vff3-pqq8-4cpq","primary_source":"","published":"2026-03-11T17:52:18.298Z"},{"affected":">= 4.0.0 < 4.10.2; >= 5.0.0 < 5.5.3","affected_versions_present":true,"cve_id":"CVE-2026-29177","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29177","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-10T20:12:39.344Z","patch_url":"https://github.com/craftcms/commerce/commit/b0683e04773f16bba6af9df18aab495fc5dde68a","primary_source":"","published":"2026-03-10T20:01:06.968Z"},{"affected":">= 4.0.0 < 4.10.2; >= 5.0.0 < 5.5.3","affected_versions_present":true,"cve_id":"CVE-2026-29176","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29176","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-10T20:12:39.491Z","patch_url":"https://github.com/craftcms/commerce/commit/da143df084563ddf0929d7c261bcc11d312e8004","primary_source":"","published":"2026-03-10T19:59:48.366Z"},{"affected":">= 5.0.0 < 5.5.3","affected_versions_present":true,"cve_id":"CVE-2026-29175","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29175","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-11T14:11:09.100Z","patch_url":"https://github.com/craftcms/commerce/commit/9f0638a4fb29ed8295a463385a7cc49ec986e33a","primary_source":"","published":"2026-03-10T19:57:36.799Z"},{"affected":">= 5.0.0 < 5.5.3","affected_versions_present":true,"cve_id":"CVE-2026-29174","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29174","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-10T20:12:39.918Z","patch_url":"https://github.com/craftcms/commerce/commit/094d69df24b925544f337c38e2ec1effcd5395c7","primary_source":"","published":"2026-03-10T19:55:54.645Z"},{"affected":">= 4.0.0 < 4.10.2; >= 5.0.0 < 5.5.3","affected_versions_present":true,"cve_id":"CVE-2026-29173","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29173","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-10T20:12:40.044Z","patch_url":"https://github.com/craftcms/commerce/commit/60cdc505c03b6fa2f59715e8c060114b66334afa","primary_source":"","published":"2026-03-10T19:54:25.064Z"},{"affected":">= 4.0.0 < 4.10.2; >= 5.0.0 < 5.5.3","affected_versions_present":true,"cve_id":"CVE-2026-29172","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29172","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-11T14:12:53.450Z","patch_url":"https://github.com/craftcms/commerce/commit/b231b920b73db023e81e5b261b894d73e865c276","primary_source":"","published":"2026-03-10T19:52:32.735Z"},{"affected":">= 4.0.0-RC1, < 4.10.1; >= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25522","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25522","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-03T19:22:34.780Z","patch_url":"https://github.com/craftcms/commerce/security/advisories/GHSA-h9r9-2pxg-cx9m","primary_source":"","published":"2026-02-03T18:10:33.911Z"},{"affected":">= 4.0.0-RC1, < 4.10.1; >= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25490","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25490","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-03T20:27:49.508Z","patch_url":"https://github.com/craftcms/commerce/commit/fa273330807807d05b564d37c88654cd772839ee","primary_source":"","published":"2026-02-03T18:09:33.290Z"},{"affected":">= 4.0.0-RC1, < 4.10.1; >= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25489","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25489","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-03T20:34:09.676Z","patch_url":"https://github.com/craftcms/commerce/commit/fa273330807807d05b564d37c88654cd772839ee","primary_source":"","published":"2026-02-03T18:07:40.168Z"},{"affected":">= 4.0.0-RC1, < 4.10.1; >= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25488","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25488","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T21:13:48.706Z","patch_url":"https://github.com/craftcms/commerce/commit/fa273330807807d05b564d37c88654cd772839ee","primary_source":"","published":"2026-02-03T18:07:25.106Z"},{"affected":">= 4.0.0-RC1, < 4.10.1; >= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25487","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25487","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T21:13:17.130Z","patch_url":"https://github.com/craftcms/commerce/commit/fa273330807807d05b564d37c88654cd772839ee","primary_source":"","published":"2026-02-03T18:07:12.401Z"},{"affected":">= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25486","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25486","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T21:10:12.885Z","patch_url":"https://github.com/craftcms/commerce/commit/fa273330807807d05b564d37c88654cd772839ee","primary_source":"","published":"2026-02-03T18:06:57.014Z"},{"affected":">= 4.0.0-RC1, < 4.10.1; >= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25485","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25485","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T16:51:07.751Z","patch_url":"https://github.com/craftcms/commerce/commit/fa273330807807d05b564d37c88654cd772839ee","primary_source":"","published":"2026-02-03T18:06:45.900Z"},{"affected":">= 4.0.0-RC1, < 4.10.1; >= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25484","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25484","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T16:51:13.282Z","patch_url":"https://github.com/craftcms/commerce/commit/7e1dedf06038c8e70dce0187b7048d4ab8ffb75c","primary_source":"","published":"2026-02-03T18:06:36.706Z"},{"affected":">= 4.0.0-RC1, < 4.10.1; >= 5.0.0, < 5.5.2","affected_versions_present":true,"cve_id":"CVE-2026-25483","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25483","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T16:51:19.008Z","patch_url":"https://github.com/craftcms/commerce/security/advisories/GHSA-8478-rmjg-mjj5","primary_source":"","published":"2026-02-03T18:05:49.411Z"},{"affected":">= 5.0.0, < 5.5.2; >= 4.0.0-RC1, < 4.10.1","affected_versions_present":true,"cve_id":"CVE-2026-25482","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25482","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T16:51:24.031Z","patch_url":"https://github.com/craftcms/commerce/commit/d94d1c9832a47a1c383e375ae87c46c13935ba65","primary_source":"","published":"2026-02-03T18:05:09.783Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"craftcms"}}
