๐Ÿ” CVE Alert

CVE-2026-63459

HIGH 8.7

Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
0th

Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live element's innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assignment before textContent is read. A lower-privilege administrator can store such markup in descriptions rendered by the Products list, Collections list, Promotions list, Payment Methods list, or Shipping Methods list, and script executes when another administrator views the affected row. This stored cross-site scripting can compromise the viewing administrator's session and enable cross-privilege or cross-channel administrative actions. This issue is fixed in version 3.6.5.

CWE CWE-79
Vendor vendurehq
Product vendure
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for vendurehq vendure

Be the first to know when new high vulnerabilities affecting vendurehq vendure are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

vendurehq / vendure
< 3.6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/vendurehq/vendure/security/advisories/GHSA-xhq9-whgq-49j5 github.com: https://github.com/vendurehq/vendure/commit/d7aa42a3f0cb524297a1a2fdf700e4aba9aca684 github.com: https://github.com/vendurehq/vendure/releases/tag/v3.6.5