Security Advisory

CVE-2026-10769

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-10 21:41:49
Last updated 2026-07-14 14:34:55
Assigner drupal
CVSS score not scored
State PUBLISHED

Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Core allows Stored XSS. This issue affects Commerce Core versions: from 3.3.0 to 3.3.6.