CVE-2026-29172 | Craft Commerce up to 4.10.2/5.5.3 Purchasables Table Endpoint orderBy sort sql injection (GHSA-j3x5-mghf-xvfw)
A vulnerability described as critical has been identified in Craft Commerce up to 4.10.2/5.5.3. This impacts the function orderBy of the component Purchasables Table Endpoint. Executing a manipulation of the argument sort can lead to sql injection.
The identification of this vulnerability is CVE-2026-29172. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.