cbcvebase.

Adobe Commerce vulnerabilities

205 known vulnerabilities affecting adobe/adobe_commerce.

Total CVEs
205
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH81MEDIUM98LOW14

Vulnerabilities

Page 11 of 11
CVE-2023-29293P4LOWCVSS 2.7≤ 2.4.4-p32023-06-15
CVE-2023-29293 [LOW] CWE-20 CVE-2023-29293: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An admin privileged attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not
nvd
CVE-2024-45149P4LOWCVSS 2.7≤ 2.4.4-p102024-10-10
CVE-2024-45149 [LOW] CWE-284 CVE-2024-45149: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not requir
nvd
CVE-2024-45134P4LOWCVSS 2.7≤ 2.4.4-p102024-10-10
CVE-2024-45134 [LOW] CWE-200 CVE-2024-45134: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Infor Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may aid in further attacks. Exploitation of this issue does not require user i
nvd
CVE-2024-45133P4LOWCVSS 2.7≤ 2.4.4-p102024-10-10
CVE-2024-45133 [LOW] CWE-284 CVE-2024-45133: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Infor Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may aid in further attacks. Exploitation of this issue does not require user i
nvd
CVE-2025-27192P4LOWCVSS 2.7≤ 2.4.8-beta22025-04-08
CVE-2025-27192 [LOW] CWE-522 CVE-2025-27192: Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affect Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential inf
nvd
Adobe Commerce vulnerabilities | cvebase