Project: 
Date: 
2026-June-03
Vulnerability: 
Cross site scripting
Affected versions: 
>= 3.3.0 < 3.3.6
CVE IDs: 
CVE-2026-10769
Description: 

The module doesn't sufficiently sanitize customer comments in the order receipt email template; this could be exploited to achieve Cross-site Scripting (XSS).

This vulnerability is mitigated by the fact that it only affects installations with Checkout (commerce_checkout) enabled, and the "Comments" checkout pane (id: customer_comments) is explicitly used, which is disabled by default.

Solution: 

Install the latest version:

Coordinated By: