{"id":"CVE-2026-32272","aliases":["GHSA-r54v-qq87-px5r"],"url":"https://o3.security/vulnerability/CVE-2026-32272","summary":"Craft Commerce: Blind SQL Injection via hasVariant/hasProduct","details":"Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct properties bypass the input sanitization blocklist added to ElementIndexesController in a prior security fix (GHSA-2453-mppf-46cj). The blocklist only strips top-level Yii2 Query properties such as where and orderBy, but hasVariant and hasProduct pass through untouched and internally call Craft::configure() on a subquery without sanitization, re-introducing SQL injection. Any authenticated control panel user can exploit this via boolean-based blind SQL injection to extract arbitrary database contents, including security keys that enable forging admin sessions for privilege escalation. This issue has been fixed in version 5.6.0.","published":"2026-04-13T20:25:50.420Z","modified":"2026-08-12T03:51:31.162131992Z","cvss":null,"epss":{"score":0.00304,"percentile":0.2321,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/commerce","fixedVersion":"5.6.0"}],"fix":{"url":"https://github.com/craftcms/commerce/pull/4232","label":"craftcms/commerce#4232"},"references":[{"type":"WEB","url":"https://github.com/craftcms/commerce/releases/tag/5.6.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32272.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2453-mppf-46cj"},{"type":"ADVISORY","url":"https://github.com/craftcms/commerce/security/advisories/GHSA-r54v-qq87-px5r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32272"},{"type":"FIX","url":"https://github.com/craftcms/commerce/pull/4232"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.162131992Z"}}