CVE-2026-25486 | Craft CMS up to 5.5.1 Store Management Section Shipping Methods Name cross site scripting (GHSA-g92v-wpv7-6w22)
A vulnerability described as problematic has been identified in Craft CMS up to 5.5.1. Affected by this vulnerability is an unknown functionality of the component Store Management Section. Executing a manipulation of the argument Shipping Methods Name can lead to cross site scripting.
This vulnerability is handled as CVE-2026-25486. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.