Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h5gm-x9wr-vhcm | Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass |
Mon, 14 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when the number POST or GET parameter is supplied. An unauthenticated attacker can submit couponCode values to actionUpdateCart for the session-based cart while omitting number, preventing creation of the IP rate-limit identity and allowing unlimited automated coupon-code guessing and enumeration. This issue is fixed in versions 4.11.2 and 5.6.5. | |
| Title | Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-14T20:06:54.939Z
Reserved: 2026-06-17T14:40:28.380Z
Link: CVE-2026-55795
Updated: 2026-09-14T19:22:17.728Z
Status : Received
Published: 2026-09-14T16:17:12.810
Modified: 2026-09-14T20:16:48.050
Link: CVE-2026-55795
No data.
OpenCVE Enrichment
No data.
Github GHSA