Critical Security Updates for Swissup Labs Magento 2 Extensions — October 2026

Following the recent StyleSmuggler security issue, we conducted a broader security review of our Magento 2 extensions and Breeze products. Our developers reviewed dozens of modules and prepared fixes for issues ranging from Low to Critical severity. We are releasing all of these updates together so you can apply them in one maintenance window.

We have not identified or received reports of these vulnerabilities being exploited on live stores, and our review found no vulnerabilities allowing arbitrary file uploads or direct server takeover. However, some issues could expose customer information, affect customer account security, allow unauthorized access to store data, or affect product pricing. Please apply these updates as soon as possible.

New: see available updates directly in the Magento Admin. The latest Swissup Core (1.14.1) includes a Module Manager that lists every installed Swissup and Breeze module, shows your installed version next to the latest released version, and moves outdated modules to the top. Update Swissup Core first and you can check your whole store at a glance instead of comparing versions by hand.

What to do, in short

  1. Update Swissup Core to 1.14.1 so you can see available updates in the Admin under Swissup → Services → Module Manager.
  2. Find out which Swissup and Breeze packages your store uses, including any theme or bundle metapackage (Argento, Argento Breeze, Firecheckout, Breeze Evolution, Breeze Enterprise).
  3. Update them to the latest versions with Composer, starting with the extensions in the “Update first” group below.
  4. Deploy and test the storefront, checkout, customer account and Admin.
  5. If you can’t update right away, temporarily disable the affected Critical and High modules, or contact us for standalone patches if your subscription has expired.

Using Argento, Argento Breeze, Firecheckout, Breeze Evolution or Breeze Enterprise? Update the metapackage too

These products are installed as metapackages: a single Composer package that pulls in many of the modules listed in this article. Your store may include Highlight, Navigation Pro, Easy Banner, Rich Snippets, AjaxPro and other affected modules even if you never installed them individually.

If you use any of the following, update the metapackage itself, not just individual modules:

  • Argento — latest version 1.54.1 (swissup/argento-m2)
  • Argento Breeze — latest version 3.2.1 (swissup/argento-breeze)
  • Firecheckout — latest version 1.36.1 (swissup/firecheckout)
  • Breeze Evolution — latest version 3.1.1 (swissup/breeze-evolution)
  • Breeze Enterprise — latest version 3.3.1 (swissup/breeze-enterprise)

Updating the metapackage with its dependencies brings every bundled module up to the fixed version. If your composer.json pins the metapackage to an exact version, raise that constraint to the latest release first, otherwise Composer will keep the old, vulnerable modules.

Step 1: Update Swissup Core to see available updates in the Admin

Swissup Core is installed automatically with every Swissup and Breeze product. Version 1.14.0 added update information to the Module Manager, and 1.14.1 includes this month’s Core security fix, so update to 1.14.1:

composer update swissup/module-core
bin/magento setup:upgrade
bin/magento setup:di:compile
bin/magento cache:flush

Then open Swissup → Services → Module Manager in the Magento Admin. For each installed module the grid shows:

  • the version installed on your store and the latest released version, with its release date;
  • links to the module’s documentation and changelog;
  • outdated modules at the top of the list, with a badge on the Swissup menu when updates are available.

The How to Update button in the Module Manager shows the exact commands to update all Swissup packages.

Step 2: Check which packages you have

The Module Manager from Step 1 is the easiest way to see which modules are outdated. You can also check from the Magento root directory on the command line:

composer show | grep -i -E "swissup|breeze"

This lists every installed Swissup and Breeze package with its current version, including metapackages. Compare the versions with the latest versions listed below.

Step 3: Update with Composer

If you have an active support and updates subscription

Test on a staging or development copy first whenever possible, then run:

composer update "swissup/*" --with-all-dependencies

This updates all Swissup packages, including theme and bundle metapackages and the modules they include.

If your subscription has expired

You have two options:

  • Renew your support and updates subscription. You will get access to the latest versions again and can update with Composer as described above. This also gives you future security and compatibility updates.
  • Request standalone security patches. Contact our support team using the account associated with your original purchase, and we will provide security patches for the affected extensions.

Step 4: Deploy and verify

After updating, complete the normal Magento deployment process:

bin/magento setup:upgrade
bin/magento setup:di:compile
bin/magento setup:static-content:deploy -f
bin/magento cache:flush

Then check the storefront, product and category pages, cart and checkout, customer registration and login, and the Admin. Open Swissup → Services → Module Manager again to confirm no modules are marked as outdated.

If you can’t update immediately

Temporarily disable the affected extensions with Critical or High severity issues until you can apply the fixes:

bin/magento module:disable <Module_Name>
bin/magento setup:upgrade

Use the module names shown by bin/magento module:status | grep -i swissup. Some modules are used by the storefront, checkout or theme, so check for storefront and checkout impact on staging before disabling them in production. If you are unsure, contact our support team and we will help.

Affected extensions

Extensions are grouped by priority. Each entry shows the latest released version and its Composer package name, followed by the security fixes and their severity. Make sure your store runs at least the version shown.

Update first

These extensions have Critical issues, or High issues affecting customer account security. Checkout Registration and AskIt are included here because of their potential impact on customer accounts, although their individual issues are classified as High.

Swissup Sold Together

Latest version: 1.11.5 (swissup/module-sold-together)

  • Security (Critical): Strengthened protection of promotional product prices in the cart.
  • Fixed promotional price calculations for configurable products.

Swissup PDF Invoice

Latest version: 1.4.12 (swissup/module-pdf-invoice)

  • Security (Critical): Strengthened document access checks to prevent unauthorized access to invoices and other documents.

Breeze Content Builder and Breeze Layout Builder

Latest versions: Breeze Content Builder 1.2.5 (swissup/module-breeze-content-builder), Breeze Layout Builder 1.3.1 (swissup/module-breeze-layout-builder)

  • Security (Critical): Added stronger authentication and access protection for previews.
  • Security (High): Improved component rendering and SVG preview security.

Swissup Checkout Registration

Latest version: 1.2.4 (swissup/module-checkout-registration)

  • Security (High): Improved protection of customer passwords during checkout registration.

Swissup AskIt

Latest version: 1.14.28 (swissup/module-askit)

  • Security (High): Improved customer identity verification in GraphQL requests.
  • Security (Medium): Strengthened content validation, permissions, and posting restrictions.
  • Security (Low): Improved protection of private information and admin output.
  • Fixed admin mass actions and notifications.
  • Changed: GraphQL voting now requires customer authentication.

High priority

Swissup ChatGPT Assistant

Latest version: 1.1.5 (swissup/module-chat-gpt-assistant)

  • Security (High): Strengthened restrictions on bulk content generation and improved admin output security.

Swissup Checkout Fields

Latest version: 1.6.18 (swissup/module-checkout-fields)

  • Security (High): Improved protection of checkout field values displayed in the admin.
  • Security (Medium): Strengthened checkout field validation and admin permissions.
  • Fixed an issue with clearing optional checkout fields.

Swissup Easy Banner

Latest version: 1.9.25 (swissup/module-easybanner)

  • Security (High): Strengthened validation of banner settings and statistics management.
  • Security (Medium): Improved image upload validation and admin action security.
  • Security (Low): Improved validation in the conditions editor.

Swissup Email

Latest version: 0.7.14 (swissup/module-email)

  • Security (High): Strengthened admin permissions for managing email services.
  • Security (Medium): Improved email log protection and SSL/TLS enforcement.
  • Security (Low): Improved password protection, access controls, and automatic log cleanup.

Swissup Email Templates

Latest version: 1.2.8 (swissup/module-email-templates)

  • Security (High): Strengthened validation when saving email templates.
  • Security (Medium): Improved template preview isolation, customer data protection, and admin permissions.
  • Security (Low): Improved output handling in the CSS preview.

Swissup GDPR

Latest version: 1.9.3 (swissup/module-gdpr)

  • Security (High): Improved output handling on the cookie settings page.
  • Security (Medium): Strengthened cookie validation and consent handling.

Swissup Helpdesk

Latest version: 1.4.9 (swissup/module-helpdesk)

  • Security (High): Improved attachment access protection and file validation.
  • Improved compatibility with Magento 2.4.8 email processing.

Swissup Highlight

Latest version: 1.11.10 (swissup/module-highlight)

  • Security (High): Improved security of storefront carousel data.
  • Security (Medium): Strengthened GraphQL query validation and limits.

Swissup Hreflang

Latest version: 1.6.13 (swissup/module-hreflang)

  • Security (High): Improved output handling of storefront hreflang links.
  • Security (Low): Improved admin form and XML sitemap output security.

Swissup Navigation Pro

Latest version: 1.19.4 (swissup/module-navigationpro)

  • Security (High): Restricted access to data through menu content directives.
  • Security (Medium): Improved admin menu security and request validation.
  • Security (Low): Reduced internal information exposed through GraphQL.
  • Fixed GraphQL menu item HTML rendering.

Swissup Order Attachments

Latest version: 1.5.4 (swissup/module-orderattachment)

  • Security (High): Strengthened attachment validation and preview protection.
  • Security (Medium): Improved upload limits, permissions, and attachment access security.
  • Security (Low): Improved storefront error handling.

Swissup Rich Snippets

Latest version: 1.8.6 (swissup/module-rich-snippets)

  • Security (High): Improved output handling in structured data (JSON-LD).

Swissup SEO Templates

Latest version: 1.7.13 (swissup/module-seo-templates)

  • Security (High): Improved input validation during SEO data generation and log management.
  • Security (Medium): Strengthened admin permissions and request protection.

Swissup Social Login

Latest version: 1.1.13 (swissup/module-social-login)

  • Security (High): Strengthened customer account linking to prevent unauthorized account associations.

Medium priority

Breeze AI

Latest version: 1.8.21 (swissup/module-breeze-ai)

  • Security (Medium): Bulk AI actions now only process the fields the wizard offers and require the matching catalog or CMS edit permission.
  • Security (Low): Changing the host of a model’s Base URL now requires entering the API key again.
  • Security (Low): The endpoint used by the MCP GraphQL tool is now restricted to http(s) addresses.
  • Security (Low): Links in generated Content Builder drafts are now checked for allowed schemes.

Breeze Theme Editor

Latest version: 1.0.17 (swissup/module-breeze-theme-editor)

  • Security (Medium): Strengthened validation of theme settings, admin permissions, and live preview access.
  • Security (Low): Reduced exposure of internal error details.

Swissup Ajax Layered Navigation

Latest version: 1.6.11 (swissup/module-ajaxlayerednavigation)

  • Security (Medium): Improved protection of AJAX filter data.
  • Security (Low): Improved cache separation, customer group handling, and filter validation.

Swissup Ajax Search

Latest version: 1.14.12 (swissup/module-ajaxsearch)

  • Security (Medium): Improved protection of category information in search filters.
  • Security (Low): Improved output handling and search suggestion visibility.
  • Fixed a layout shift in the Breeze and Luma search form.

Swissup AjaxPro

Latest version: 1.7.44 (swissup/module-ajaxpro)

  • Security (Medium): Strengthened AJAX request URL validation.
  • Security (Low): Improved product visibility protection in Quick View and add-to-cart responses.

Swissup Cache Warmer

Latest version: 1.0.42 (swissup/module-cache-warmer)

  • Security (Medium): Improved validation and limits for page statistics requests.
  • Security (Low): Improved password storage, secure connections, and crawler log cleanup.

Swissup Delete Orders

Latest version: 1.3.6 (swissup/module-delete-orders)

  • Security (Medium): Improved protection of admin order management actions.
  • Simplified logging configuration.

Swissup Easy Flags

Latest version: 1.4.6 (swissup/module-easyflags)

  • Security (Medium): Improved image validation and output handling.
  • Changed: Magento versions earlier than 2.3 are no longer supported.

Swissup Easy Tabs

Latest version: 1.13.6 (swissup/module-easytabs)

  • Security (Medium): Improved product visibility restrictions and GraphQL access controls.

Swissup GeoIP

Latest version: 1.6.3 (swissup/module-geoip)

  • Security (Medium): Improved handling of proxy IP headers.

Swissup Knowledge Base

Latest version: 1.1.47 (swissup/module-knowledge-base)

  • Security (Medium): Strengthened access restrictions for articles and categories.
  • Security (Low): Improved sitemap filtering, error handling, and GraphQL restrictions.

Swissup Pro Labels

Latest version: 1.10.3 (swissup/module-pro-labels)

  • Security (Medium): Improved output handling, validation of label settings, image uploads, and admin permissions.
  • Fixed a possible PHP error on category pages.
  • Note: Editing existing labels now applies stricter validation.

Swissup SEO Cross Links

Latest version: 1.2.1 (swissup/module-seo-cross-links)

  • Security (Medium): Strengthened URL validation.

Swissup Speculation Rules

Latest version: 1.0.5 (swissup/module-speculation-rules)

  • Security (Medium): Strengthened configuration validation.
  • Security (Low): Improved default prerender exclusions.

Swissup Subscribe at Checkout

Latest version: 1.3.7 (swissup/module-subscribe-at-checkout)

  • Security (Medium): Improved guest newsletter subscription handling.
  • Improved subscription settings and customer account integration.

Low priority

Swissup Core

Latest version: 1.14.1 (swissup/module-core)

  • Security (Low): Improved validation and output handling in Module Manager.

Swissup MySQL Legacy Search

Latest version: 1.1.14 (swissup/module-search-mysql-legacy)

  • Security (Low): Improved search request limits.
  • Fixed multi-word search handling.

Swissup Pagespeed

Latest version: 1.20.1 (swissup/module-pagespeed)

  • Security (Low): Improved debug settings, critical CSS generation security, request handling, and Content Security Policy rules.

Need assistance?

Updating Magento extensions can require planning, especially on stores with many third-party modules. Our support team can help you identify affected extensions and get the updates or standalone patches you need. Please contact support on the site where you bought your products:

Please do not delay applying Critical and High priority fixes. Thank you for trusting Swissup Labs. We will continue reviewing and improving the security of our products.