Adobe Commerce vulnerabilities
198 known vulnerabilities affecting adobe/commerce.
Total CVEs
198
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
4
Severity breakdown
CRITICAL15HIGH67MEDIUM102LOW14
Vulnerabilities
Page 6 of 10
CVE-2023-26366P3MEDIUMCVSS 6.8v2.3.7v2.4.0+7 more2023-10-13
CVE-2023-26366 [MEDIUM] CWE-918 CVE-2023-26366: Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) an
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A high-privileged authenticated attacker can force the application to make arbitrary requests via injection of a
nvd
CVE-2022-35698P4MEDIUMCVSS 5.4fixed in 2.4.4v2.4.4+1 more2022-10-14
CVE-2022-35698 [MEDIUM] CWE-79 CVE-2022-35698: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cros
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
nvd
CVE-2025-49558P3MEDIUMCVSS 5.9fixed in 2.4.4v2.4.4+4 more2025-08-12
CVE-2025-49558 [MEDIUM] CWE-367 CVE-2025-49558: Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlie
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability by manipulating the timing between the check of a resource's state and its
nvd
CVE-2024-20718P4MEDIUMCVSS 6.5v2.4.4v2.4.5+1 more2024-02-15
CVE-2024-20718 [MEDIUM] CWE-352 CVE-2024-20718: Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Reques
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a victim into performing actions they did not intend to do, which could be used to bypass security measures and gain
nvd
CVE-2026-21286P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+5 more2026-03-11
CVE-2026-21286 [MEDIUM] CWE-863 CVE-2026-21286: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized view access of data. Exploitation of thi
nvd
CVE-2021-39864P4MEDIUMCVSS 6.5≤ 2.3.7v2.3.7+2 more2021-10-15
CVE-2021-39864 [MEDIUM] CWE-352 CVE-2021-39864: Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are af
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for success
nvd
CVE-2026-21293P4MEDIUMCVSS 5.5fixed in 2.4.4v2.4.4+5 more2026-03-11
CVE-2026-21293 [MEDIUM] CWE-918 CVE-2026-21293: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and access unauthorized resources. Expl
nvd
CVE-2024-45131P4MEDIUMCVSS 5.4v2.3.7v2.4.0+7 more2024-10-10
CVE-2024-45131 [MEDIUM] CWE-863 CVE-2024-45131: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality and integrity. Exploitation of this issue
nvd
CVE-2025-24437P4MEDIUMCVSS 5.4v2.4.4v2.4.5+3 more2025-02-11
CVE-2025-24437 [MEDIUM] CWE-863 CVE-2025-24437: Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affect
Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view or modify select information. Exploitation of this issue does not require user interactio
nvd
CVE-2026-21310P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+5 more2026-03-11
CVE-2026-21310 [MEDIUM] CWE-20 CVE-2026-21310: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-47999P4MEDIUMCVSS 4.8v2.4.4v2.4.4-p1+74 more2026-07-14
CVE-2026-47999 [MEDIUM] CWE-79 CVE-2026-47999: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2024-34106P4MEDIUMCVSS 5.3v2.3.7v2.4.0+6 more2024-06-13
CVE-2024-34106 [MEDIUM] CWE-863 CVE-2024-34106: Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to gain unauthorized access or perform actions with the privileges of another user. Exploitation of this issue does not require u
nvd
CVE-2024-45128P4MEDIUMCVSS 5.4v2.3.7v2.4.0+7 more2024-10-10
CVE-2024-45128 [MEDIUM] CWE-863 CVE-2024-45128: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity and availability. Exploitation of this issue doe
nvd
CVE-2026-21294P4MEDIUMCVSS 5.5fixed in 2.4.4v2.4.4+5 more2026-03-11
CVE-2026-21294 [MEDIUM] CWE-918 CVE-2026-21294: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and bypass security controls. Exploitat
nvd
CVE-2025-49559P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+4 more2025-08-12
CVE-2025-49559 [MEDIUM] CWE-22 CVE-2025-49559: Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlie
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to modify limited data. Exploitation of this
nvd
CVE-2025-27191P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+4 more2025-04-08
CVE-2025-27191 [MEDIUM] CWE-284 CVE-2025-27191: Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affect
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user int
nvd
CVE-2025-27190P4MEDIUMCVSS 5.3v2.4.4v2.4.5+3 more2025-04-08
CVE-2025-27190 [MEDIUM] CWE-284 CVE-2025-27190: Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affect
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user int
nvd
CVE-2025-27206P4MEDIUMCVSS 5.3v2.4.4v2.4.5+3 more2025-06-10
CVE-2025-27206 [MEDIUM] CWE-284 CVE-2025-27206: Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Exploitation of this issue does not require user interac
nvd
CVE-2026-48000P4MEDIUMCVSS 6.1v2.4.4v2.4.4-p1+74 more2026-07-14
CVE-2026-48000 [MEDIUM] CWE-601 CVE-2026-48000: Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result i
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site, potentially enabling credential theft and account takeover. Exploitation of this issue requires user interaction in that a
nvd
CVE-2022-34259P4MEDIUMCVSS 5.3≥ 2.3.0, < 2.3.7≥ 2.4.0, < 2.4.3+3 more2022-08-16
CVE-2022-34259 [MEDIUM] CWE-284 CVE-2022-34259: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user in
nvd