cbcvebase.

Adobe Commerce vulnerabilities

184 known vulnerabilities affecting adobe/commerce.

Total CVEs
184
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL11HIGH66MEDIUM94LOW13

Vulnerabilities

Page 10 of 10
CVE-2022-34257MEDIUMCVSS 6.1≥ 2.3.0, < 2.3.7≥ 2.4.0, < 2.4.3+3 more2022-08-16
CVE-2022-34257 [MEDIUM] CWE-79 CVE-2022-34257: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing
nvd
CVE-2022-34258MEDIUMCVSS 4.8≥ 2.3.0, < 2.3.7≥ 2.4.0, < 2.4.3+3 more2022-08-16
CVE-2022-34258 [MEDIUM] CWE-79 CVE-2022-34258: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse
nvd
CVE-2022-24086CRITICALCVSS 9.8KEVPoCfixed in 2.3.0≥ 2.3.3, ≤ 2.3.6+3 more2022-02-16
CVE-2022-24086 [CRITICAL] CWE-20 CVE-2022-24086: Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an imprope Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
nvd
CVE-2021-39864MEDIUMCVSS 6.5≤ 2.3.7v2.3.7+2 more2021-10-15
CVE-2021-39864 [MEDIUM] CWE-352 CVE-2021-39864: Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are af Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for success
nvd