CVE-2026-29174 | Craft Commerce up to 5.5.2 Commerce Inventory Section addOrderBy sql injection (GHSA-pmgj-gmm4-jh6j)
A vulnerability classified as critical has been found in Craft Commerce up to 5.5.2. Affected is the function addOrderBy of the component Commerce Inventory Section. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-29174. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.